Back

HIGH

OpenSSH privilege separation flaw

Published Nov 8, 2006

Description

Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been successful, which might allow attackers to bypass authentication. NOTE: as of 20061108, it is believed that this issue is only exploitable by leveraging vulnerabilities in the unprivileged process, which are not known to exist.

Affected products

Remediation

Red Hat statement

This issue did not affect Red Hat Enterprise Linux 2.1. Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.

Metrics

Weaknesses (0)

No CWE recorded.

References (33)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 8, 2006
Updated Aug 7, 2024
Reserved Nov 8, 2006
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 7, 2006