Race condition in OpenSSH - CVE-2006-5051

 

Race condition in OpenSSH - CVE-2006-5051

Published: July 1, 2024 / Updated: January 8, 2025


Vulnerability identifier: #VU93515
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2006-5051
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in sshd when GSSAPI authentication is enabled. A remote attacker can send specially crafted requests to the daemon, trigger a race condition and execute arbitrary code on the system.


Affected software

OpenSSH
IBM i
Anolis OS
Junos OS
Junos OS Evolved
Athonet IMS
Athonet Mobile Core
openssh
openssh-askpass
openssh-clients
openssh-keycat
openssh-server
openssh-sk-dummy
openssh-doc
Citrix Netscaler ADC
NetScaler Console (formerly NetScaler ADM)
Citrix NetScaler Gateway

How to mitigate CVE-2006-5051

Install updates from vendor's website.

OpenSSH - update to 4.4p1
Junos OS - addressed in versions 24.2R1-S2, 24.2R2, 24.4R1
Junos OS Evolved - addressed in versions 24.2R1-S2-EVO, 24.2R2-EVO, 24.4R1-EVO
Athonet IMS - update to 1.24.1.1
Athonet Mobile Core - update to 1.24.1.1
openssh - addressed in versions 9.3p2-2, 9.6p1-2
openssh-askpass - addressed in versions 9.3p2-2, 9.6p1-2
openssh-clients - addressed in versions 9.3p2-2, 9.6p1-2
openssh-keycat - addressed in versions 9.3p2-2, 9.6p1-2
openssh-server - addressed in versions 9.3p2-2, 9.6p1-2
openssh-sk-dummy - addressed in versions 9.3p2-2, 9.6p1-2
openssh-doc - addressed in versions 9.3p2-2, 9.6p1-2
Citrix Netscaler ADC - addressed in versions 12.1-55.309, 13.0-92.31, 13.1-37.190, 13.1-53.24, 14.1-25.56
NetScaler Console (formerly NetScaler ADM) - addressed in versions 13.0-92.31, 13.1-53.24, 14.1-25.56
Citrix NetScaler Gateway - update to 14.1-25.56

External References

Related Security Bulletins