cbcvebase.
CVE-2024-6387
published 2024-07-01

CVE-2024-6387: A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an…

high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EXPLOIT
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
almalinuxalmalinux
amazonamazon_linux
applemacos>= 12.0 < 12.7.612.7.6
applemacos>= 13.0 < 13.6.813.6.8
applemacos>= 14.0 < 14.614.6
applemacos_monterey
applemacos_sonoma
applemacos_ventura
aristaeos4.32.0 – 4.32.1f
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianopenssh< openssh 1:9.2p1-2+deb12u3 (bookworm)openssh 1:9.2p1-2+deb12u3 (bookworm)
debianopenssh
freebsdfreebsd< 13.013.0
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd>= 13.1 < 13.313.3
freebsdfreebsd>= 13.3-RELEASE < p5p5
freebsdfreebsd>= 14.0-RELEASE < p9p9

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vulncheck8.1HIGH