Back to search
CVE-2006-5794
Published: Nov 8, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been successful, which might allow attackers to bypass authentication. NOTE: as of 20061108, it is believed that this issue is only exploitable by leveraging vulnerabilities in the unprivileged process, which are not known to exist.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
1017183
vdb-entry
x_refsource_SECTRACK
22932
third-party-advisory
x_refsource_SECUNIA
22773
third-party-advisory
x_refsource_SECUNIA
http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html
x_refsource_CONFIRM
https://issues.rpath.com/browse/RPL-766
x_refsource_CONFIRM
22872
third-party-advisory
x_refsource_SECUNIA
22772
third-party-advisory
x_refsource_SECUNIA
ADV-2006-4399
vdb-entry
x_refsource_VUPEN
23513
third-party-advisory
x_refsource_SECUNIA
23680
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2006:026
vendor-advisory
x_refsource_SUSE
24055
third-party-advisory
x_refsource_SECUNIA
22771
third-party-advisory
x_refsource_SECUNIA
openssh-separation-verificaton-weakness(30120)
vdb-entry
x_refsource_XF
http://support.avaya.com/elmodocs2/security/ASA-2007-048.htm
x_refsource_CONFIRM
ADV-2006-4400
vdb-entry
x_refsource_VUPEN
20061109 rPSA-2006-0207-1 openssh openssh-client openssh-server
mailing-list
x_refsource_BUGTRAQ
22778
third-party-advisory
x_refsource_SECUNIA
22814
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:11840
vdb-entry
signature
x_refsource_OVAL
20956
vdb-entry
x_refsource_BID
MDKSA-2006:204
vendor-advisory
x_refsource_MANDRIVA
http://www.openssh.org/txt/release-4.5
x_refsource_CONFIRM
OpenPKG-SA-2006.032
vendor-advisory
x_refsource_OPENPKG
http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html
x_refsource_CONFIRM
RHSA-2006:0738
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now