CVE-2006-4924: High severity OpenBSD OpenSSH vulnerability
sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not properly handled by the CRC compensation attack detector.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4924?
CVE-2006-4924 is classified as a high severity vulnerability due to its potential to cause denial of service.
How does CVE-2006-4924 affect OpenSSH?
CVE-2006-4924 allows remote attackers to consume CPU resources, leading to denial of service via specially crafted SSH packets.
Which versions of OpenSSH are affected by CVE-2006-4924?
CVE-2006-4924 affects versions of OpenSSH prior to 4.4 that utilize SSH protocol version 1.
How can I mitigate CVE-2006-4924?
Mitigation for CVE-2006-4924 involves upgrading to OpenSSH version 4.4 or later, which includes fixes for this vulnerability.
Is CVE-2006-4924 related to other vulnerabilities in SSH?
While CVE-2006-4924 specifically targets SSH protocol version 1, it highlights underlying weaknesses in older SSH implementations that may be exploited.