SSH: OpenSSH sshd Identical Blocks Denial of Service

This signature detects attempts to exploit a known vulnerability against OpenSSH. A successful attack can result in a denial-of-service condition.

Extended Description

OpenSSH is prone to a remote denial-of-service vulnerability because it fails to properly handle incoming duplicate blocks. Remote attackers may exploit this issue to consume excessive CPU resources, potentially denying service to legitimate users. This issue occurs only when OpenSSH is configured to accept SSH Version One traffic.

Affected Products

Blue_coat_systems proxysg,Freebsd freebsd

References

BugTraq: 20216

CVE: CVE-2006-4924

Short Name
SSH:OPENSSH:BLOCK-DOS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SSH
Keywords
Blocks CVE-2006-4924 Denial Identical OpenSSH Service bid:20216 of sshd
Release Date
09/27/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
Vendors

Red_hat

Blue_coat_systems

Sco

Suse

Ibm

Gentoo

Globus

Openssh

Rpath

Turbolinux

Avaya

Openpkg

Sgi

Slackware

Freebsd

Ubuntu

Mandriva

Openbsd

Sun

Debian

Apple

CVSS Score

7.8

Found a potential security threat?