← All CVEs

CVE-2006-4924

high · 7.8

sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not properly handled by the CRC compensation attack detector.

7.8
CVSS
37.5%
EPSS (exploit prob.)
98th
EPSS percentile
2006-09-27
Published

AV:N/AC:L/Au:N/C:N/I:N/A:C

Weaknesses

CWE-399

Affected products

VendorProductAffected versions
openbsdopenssh1.2
openbsdopenssh1.2.1
openbsdopenssh1.2.2
openbsdopenssh1.2.3
openbsdopenssh1.2.27
openbsdopenssh2.1
openbsdopenssh2.1.1
openbsdopenssh2.2
openbsdopenssh2.3
openbsdopenssh2.5
openbsdopenssh2.5.1
openbsdopenssh2.5.2
openbsdopenssh2.9
openbsdopenssh2.9.9
openbsdopenssh2.9.9p2
openbsdopenssh2.9p1
openbsdopenssh2.9p2
openbsdopenssh3.0
openbsdopenssh3.0.1
openbsdopenssh3.0.1p1
openbsdopenssh3.0.2
openbsdopenssh3.0.2p1
openbsdopenssh3.0p1
openbsdopenssh3.1
openbsdopenssh3.1p1
openbsdopenssh3.2
openbsdopenssh3.2.2
openbsdopenssh3.2.2p1
openbsdopenssh3.2.3p1
openbsdopenssh3.3
openbsdopenssh3.3p1
openbsdopenssh3.4
openbsdopenssh3.4p1
openbsdopenssh3.5
openbsdopenssh3.5p1
openbsdopenssh3.6
openbsdopenssh3.6.1
openbsdopenssh3.6.1p1
openbsdopenssh3.6.1p2
openbsdopenssh3.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-4924