openssh DoS
Published Sep 27, 2006
7.8
HIGHCVSS 2.0
EPSS 37.54%
Description
sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not properly handled by the CRC compensation attack detector.
Affected products
No data.
- 1.2
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.27
- 2.1
- 2.1.1
- 2.2
- 2.3
- 2.5
- 2.5.1
- 2.5.2
- 2.9
- 2.9.9
- 2.9.9p2
- 2.9p1
- 2.9p2
- 3.0
- 3.0.1
- 3.0.1p1
- 3.0.2
- 3.0.2p1
- 3.0p1
- 3.1
- 3.1p1
- 3.2
- 3.2.2
- 3.2.2p1
- 3.2.3p1
- 3.3
- 3.3p1
- 3.4
- 3.4p1
- 3.5
- 3.5p1
- 3.6
- 3.6.1
- 3.6.1p1
- 3.6.1p2
- 3.7
- 3.7.1
- 3.7.1p1
- 3.7.1p2
- 3.8
- 3.8.1
- 3.8.1p1
- 3.9
- 3.9.1
- 3.9.1p1
- 4.0
- 4.0p1
- 4.1p1
- 4.2
- 4.2p1
- 4.3
- 4.3p1
No data.
Red Hat Enterprise Linux 2.1
openssh-0:3.1p1-21
Fixed · RHSA-2006:0698
Red Hat Enterprise Linux 3
openssh-0:3.6.1p2-33.30.12
Fixed · RHSA-2006:0697
Red Hat Enterprise Linux 4
openssh-0:3.9p1-8.RHEL4.17
Fixed · RHSA-2006:0697
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | openssh-0:3.1p1-21 | Fixed | RHSA-2006:0698 |
| Red Hat Enterprise Linux 3 | openssh-0:3.6.1p2-33.30.12 | Fixed | RHSA-2006:0697 |
| Red Hat Enterprise Linux 4 | openssh-0:3.9p1-8.RHEL4.17 | Fixed | RHSA-2006:0697 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (42 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 37.54% (0.37542) | 98.49th | v5 (v2026.06.15) |
| Aug 25, 2026 | 37.54% (0.37542) | 98.42th | v5 (v2026.06.15) |
| Jun 15, 2026 | 33.91% (0.33913) | 98.17th | v5 (v2026.06.15) |
| Mar 4, 2026 | 54.32% (0.54323) | 97.97th | v4 (v2025.03.14) |
| Mar 1, 2026 | 50.85% (0.50852) | 97.82th | v4 (v2025.03.14) |
| Feb 7, 2026 | 54.32% (0.54323) | 97.95th | v4 (v2025.03.14) |
| Feb 4, 2026 | 47.95% (0.47954) | 97.63th | v4 (v2025.03.14) |
| Feb 1, 2026 | 50.85% (0.50852) | 97.79th | v4 (v2025.03.14) |
| Jan 4, 2026 | 47.95% (0.47954) | 97.61th | v4 (v2025.03.14) |
| Jan 1, 2026 | 50.85% (0.50852) | 97.77th | v4 (v2025.03.14) |
| Dec 4, 2025 | 47.95% (0.47954) | 97.58th | v4 (v2025.03.14) |
| Dec 1, 2025 | 50.85% (0.50852) | 97.74th | v4 (v2025.03.14) |
| Nov 4, 2025 | 47.95% (0.47954) | 97.58th | v4 (v2025.03.14) |
| Nov 1, 2025 | 50.85% (0.50852) | 97.73th | v4 (v2025.03.14) |
| Oct 4, 2025 | 47.95% (0.47954) | 97.63th | v4 (v2025.03.14) |
| Oct 1, 2025 | 50.85% (0.50852) | 97.79th | v4 (v2025.03.14) |
| Sep 5, 2025 | 47.03% (0.47027) | 97.61th | v4 (v2025.03.14) |
| Sep 1, 2025 | 49.94% (0.49936) | 97.76th | v4 (v2025.03.14) |
| Aug 4, 2025 | 46.44% (0.46437) | 97.56th | v4 (v2025.03.14) |
| Aug 1, 2025 | 49.35% (0.49351) | 97.72th | v4 (v2025.03.14) |
| Jul 30, 2025 | 46.44% (0.46437) | 97.56th | v4 (v2025.03.14) |
| Jul 8, 2025 | 43.19% (0.43189) | 97.35th | v4 (v2025.03.14) |
| Jun 1, 2025 | 46.12% (0.46116) | 97.50th | v4 (v2025.03.14) |
| Mar 30, 2025 | 44.42% (0.44416) | 97.29th | v4 (v2025.03.14) |
| Mar 29, 2025 | 32.70% (0.32699) | 95.10th | v4 (v2025.03.14) |
| Mar 24, 2025 | 44.42% (0.44416) | 97.27th | v4 (v2025.03.14) |
| Mar 17, 2025 | 42.63% (0.42633) | 97.16th | v4 (v2025.03.14) |
| Jan 16, 2025 | 85.20% (0.85204) | 98.78th | v3 (v2023.03.01) |
| Dec 17, 2024 | 86.64% (0.86642) | 98.84th | v3 (v2023.03.01) |
| Aug 17, 2024 | 93.31% (0.93306) | 99.13th | v3 (v2023.03.01) |
| Apr 8, 2024 | 94.60% (0.94601) | 99.21th | v3 (v2023.03.01) |
| Feb 20, 2024 | 91.23% (0.91234) | 98.78th | v3 (v2023.03.01) |
| Dec 31, 2023 | 92.57% (0.92567) | 98.80th | v3 (v2023.03.01) |
| Nov 22, 2023 | 93.62% (0.93615) | 98.87th | v3 (v2023.03.01) |
| Jul 31, 2023 | 93.95% (0.93946) | 98.77th | v3 (v2023.03.01) |
| Jun 23, 2023 | 93.60% (0.93601) | 98.69th | v3 (v2023.03.01) |
| May 16, 2023 | 93.69% (0.93691) | 98.65th | v3 (v2023.03.01) |
| Apr 8, 2023 | 93.75% (0.93750) | 98.61th | v3 (v2023.03.01) |
| Mar 7, 2023 | 93.51% (0.93508) | 98.51th | v3 (v2023.03.01) |
| Mar 6, 2023 | 15.27% (0.15272) | 95.95th | v2 (v2022.01.01) |
| Apr 1, 2022 | 15.27% (0.15272) | 95.58th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.27% (0.15272) | 91.38th | v2 (v2022.01.01) |
References (83)
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-06:22.openssh.asc vendor-advisoryx_refsource_FREEBSD
- ftp://ftp.sco.com/pub/unixware7/714/security/p534336/p534336.txt vendor-advisoryx_refsource_SCO
- ftp://patches.sgi.com/support/free/security/advisories/20061001-01-P.asc vendor-advisoryx_refsource_SGI
- http://blogs.sun.com/security/entry/sun_alert_102962_security_vulnerability x_refsource_CONFIRM
- http://bugs.gentoo.org/show_bug.cgi?id=148228 x_refsource_CONFIRM
- http://docs.info.apple.com/article.html?artnum=305214 x_refsource_CONFIRM
- http://itrc.hp.com/service/cki/docDisplay.do?docId=c00815112 vendor-advisoryx_refsource_HP
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html vendor-advisoryx_refsource_APPLE
- http://marc.info/?l=openssh-unix-dev&m=115939141729160&w=2 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/21923 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22091 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22116 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22158 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22164 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22183 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22196 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22208 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22236 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22245 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22270 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22298 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22352 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22362 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22487 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22495 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22823 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22926 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23038 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23241 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23340 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/23680 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24479 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24799 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24805 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/25608 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29371 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34274 third-party-advisoryx_refsource_SECUNIA
- http://security.freebsd.org/advisories/FreeBSD-SA-06%3A22.openssh.asc vendor-advisoryx_refsource_FREEBSD
- http://security.gentoo.org/glsa/glsa-200609-17.xml vendor-advisoryx_refsource_GENTOO
- http://security.gentoo.org/glsa/glsa-200611-06.xml vendor-advisoryx_refsource_GENTOO
- http://securitytracker.com/id?1016931 vdb-entryx_refsource_SECTRACK
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.592566 vendor-advisoryx_refsource_SLACKWARE
- http://sourceforge.net/forum/forum.php?forum_id=681763 x_refsource_CONFIRM
- http://sourceforge.net/project/shownotes.php?release_id=461863&group_id=69227 x_refsource_CONFIRM
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102962-1 vendor-advisoryx_refsource_SUNALERT
- http://support.avaya.com/elmodocs2/security/ASA-2006-216.htm x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2006-262.htm x_refsource_CONFIRM
- http://www-unix.globus.org/mail_archive/security-announce/2007/04/msg00000.html mailing-listx_refsource_MLIST
- http://www.debian.org/security/2006/dsa-1189 vendor-advisoryx_refsource_DEBIANPatch
- http://www.debian.org/security/2006/dsa-1212 vendor-advisoryx_refsource_DEBIANPatch
- http://www.kb.cert.org/vuls/id/787448 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:179 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2006_24_sr.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2006_62_openssh.html vendor-advisoryx_refsource_SUSE
- http://www.openbsd.org/errata.html#ssh vendor-advisoryx_refsource_OPENBSD
- http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.022-openssh.html vendor-advisoryx_refsource_OPENPKG
- http://www.osvdb.org/29152 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2006-0697.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2006-0698.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/447153/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/20216 vdb-entryx_refsource_BIDExploitPatch
- http://www.trustix.org/errata/2006/0054 vendor-advisoryx_refsource_TRUSTIX
- http://www.ubuntu.com/usn/usn-355-1 vendor-advisoryx_refsource_UBUNTU
- http://www.us-cert.gov/cas/techalerts/TA07-072A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html x_refsource_CONFIRM
- http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2006/3777 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/4401 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2006/4869 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/0930 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/1332 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2007/2119 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/0740 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-4924 Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=207955 x_refsource_MISCPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=207957 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29158 vdb-entryx_refsource_XF
- https://hypersonic.bluecoat.com/support/securityadvisories/ssh_server_on_sg x_refsource_CONFIRM
- https://issues.rpath.com/browse/RPL-661 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2006-4924
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10462 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1193 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-4924
Change history (0)
No recorded changes yet.