CVE-2006-0353
lsh-server - filedescriptor leak
EPSS 0.35%
Description
unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.
How to fix CVE-2006-0353
To remediate CVE-2006-0353, upgrade the affected package to a fixed version below.
- Debian/lsh-utils—upgrade to 2.0.1cdbs-4 or later
- Debian/lsh-utils—upgrade to 2.0.1-3sarge1 or later
Is CVE-2006-0353 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.0.1cdbs-4
- from 0, < 2.0.1-3sarge1