CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
Percentile
91.8%
CentOS Errata and Security Advisory CESA-2006:0738
OpenSSH is OpenBSD’s SSH (Secure SHell) protocol implementation. This
package includes the core files necessary for both the OpenSSH client and
server.
An authentication flaw was found in OpenSSH’s privilege separation monitor.
If it ever becomes possible to alter the behavior of the unprivileged
process when OpenSSH is using privilege separation, an attacker may then be
able to login without possessing proper credentials. (CVE-2006-5794)
Please note that this flaw by itself poses no direct threat to OpenSSH
users. Without another security flaw that could allow an attacker to alter
the behavior of OpenSSH’s unprivileged process, this flaw cannot be
exploited. There are currently no known flaws to exploit this behavior.
However, we have decided to issue this erratum to fix this flaw to reduce
the security impact if an unprivileged process flaw is ever found.
Users of openssh should upgrade to these updated packages, which contain a
backported patch to resolve this issue.
Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2006-November/075562.html
https://lists.centos.org/pipermail/centos-announce/2006-November/075563.html
https://lists.centos.org/pipermail/centos-announce/2006-November/075564.html
https://lists.centos.org/pipermail/centos-announce/2006-November/075566.html
https://lists.centos.org/pipermail/centos-announce/2006-November/075567.html
https://lists.centos.org/pipermail/centos-announce/2006-November/075569.html
https://lists.centos.org/pipermail/centos-announce/2006-November/075572.html
https://lists.centos.org/pipermail/centos-announce/2006-November/075573.html
Affected packages:
openssh
openssh-askpass
openssh-askpass-gnome
openssh-clients
openssh-server
Upstream details at:
https://access.redhat.com/errata/RHSA-2006:0738
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
CentOS | 3 | i386 | openssh | < 3.6.1p2-33.30.13 | openssh-3.6.1p2-33.30.13.i386.rpm |
CentOS | 3 | i386 | openssh-askpass | < 3.6.1p2-33.30.13 | openssh-askpass-3.6.1p2-33.30.13.i386.rpm |
CentOS | 3 | i386 | openssh-askpass-gnome | < 3.6.1p2-33.30.13 | openssh-askpass-gnome-3.6.1p2-33.30.13.i386.rpm |
CentOS | 3 | i386 | openssh-clients | < 3.6.1p2-33.30.13 | openssh-clients-3.6.1p2-33.30.13.i386.rpm |
CentOS | 3 | i386 | openssh-server | < 3.6.1p2-33.30.13 | openssh-server-3.6.1p2-33.30.13.i386.rpm |
CentOS | 3 | x86_64 | openssh | < 3.6.1p2-33.30.13 | openssh-3.6.1p2-33.30.13.x86_64.rpm |
CentOS | 3 | x86_64 | openssh-askpass | < 3.6.1p2-33.30.13 | openssh-askpass-3.6.1p2-33.30.13.x86_64.rpm |
CentOS | 3 | x86_64 | openssh-askpass-gnome | < 3.6.1p2-33.30.13 | openssh-askpass-gnome-3.6.1p2-33.30.13.x86_64.rpm |
CentOS | 3 | x86_64 | openssh-clients | < 3.6.1p2-33.30.13 | openssh-clients-3.6.1p2-33.30.13.x86_64.rpm |
CentOS | 3 | x86_64 | openssh-server | < 3.6.1p2-33.30.13 | openssh-server-3.6.1p2-33.30.13.x86_64.rpm |