Back to search
CVE-2006-5052
Published: Sep 27, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows remote attackers to determine the validity of usernames via unknown vectors involving a GSSAPI "authentication abort."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20245
vdb-entry
x_refsource_BID
20061005 rPSA-2006-0185-1 gnome-ssh-askpass openssh openssh-client openssh-server
mailing-list
x_refsource_BUGTRAQ
http://openssh.org/txt/release-4.4
x_refsource_CONFIRM
TA07-072A
third-party-advisory
x_refsource_CERT
GLSA-200611-06
vendor-advisory
x_refsource_GENTOO
SUSE-SA:2006:062
vendor-advisory
x_refsource_SUSE
APPLE-SA-2007-03-13
vendor-advisory
x_refsource_APPLE
29266
vdb-entry
x_refsource_OSVDB
http://docs.info.apple.com/article.html?artnum=305214
x_refsource_CONFIRM
27588
third-party-advisory
x_refsource_SECUNIA
https://issues.rpath.com/browse/RPL-681
x_refsource_CONFIRM
1016939
vdb-entry
x_refsource_SECTRACK
http://support.avaya.com/elmodocs2/security/ASA-2007-527.htm
x_refsource_CONFIRM
oval:org.mitre.oval:def:10178
vdb-entry
signature
x_refsource_OVAL
openssh-gssapi-user-enumeration(29255)
vdb-entry
x_refsource_XF
22495
third-party-advisory
x_refsource_SECUNIA
22823
third-party-advisory
x_refsource_SECUNIA
SSA:2006-272-02
vendor-advisory
x_refsource_SLACKWARE
[openssh-unix-dev] 20060927 Announce: OpenSSH 4.4 released
mailing-list
x_refsource_MLIST
RHSA-2007:0703
vendor-advisory
x_refsource_REDHAT
RHSA-2006:0697
vendor-advisory
x_refsource_REDHAT
ADV-2007-0930
vdb-entry
x_refsource_VUPEN
28320
third-party-advisory
x_refsource_SECUNIA
22173
third-party-advisory
x_refsource_SECUNIA
RHSA-2007:0540
vendor-advisory
x_refsource_REDHAT
22158
third-party-advisory
x_refsource_SECUNIA
24479
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now