CVE-2006-0883: Medium severity OpenBSD OpenSSH vulnerability
OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0883?
CVE-2006-0883 is classified as a denial of service vulnerability.
How do I fix CVE-2006-0883?
To mitigate CVE-2006-0883, update OpenSSH to a patched version that resolves this issue.
Which versions are affected by CVE-2006-0883?
CVE-2006-0883 specifically affects OpenSSH on FreeBSD 5.3 and 5.4 when used with OpenPAM.
What type of attack does CVE-2006-0883 facilitate?
CVE-2006-0883 allows remote attackers to execute a denial of service attack by causing connection refusals on the SSH server.
Is there a known exploit for CVE-2006-0883?
Yes, attackers can exploit CVE-2006-0883 by repeatedly connecting to the vulnerable SSH server during PAM authentication.