PT-2006-1064 · Ssh+2 · Ssh Tectia Server+5

Publicado

2006-02-15

·

Atualizado

2017-07-20

·

CVE-2006-0705

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: AttachmateWRQ Reflection for Secure IT UNIX Server versions prior to 6.0.0.9 AttachmateWRQ Reflection for Secure IT Windows Server versions prior to 6.0 build 38 F-Secure SSH Server for Windows versions prior to 5.3 build 35 F-Secure SSH Server for UNIX versions 3.0 through 5.0.8 SSH Tectia Server versions prior to 4.3.7 SSH Shell Server versions prior to 3.2.9
Description: The issue allows remote authenticated users to execute arbitrary commands via crafted filenames and the stat command, potentially leading to a breach of confidentiality, integrity, and availability of protected information. This can be exploited by a remote attacker who has passed the authentication procedure.
Recommendations: For AttachmateWRQ Reflection for Secure IT UNIX Server versions prior to 6.0.0.9, update to version 6.0.0.9 or later. For AttachmateWRQ Reflection for Secure IT Windows Server versions prior to 6.0 build 38, update to version 6.0 build 38 or later. For F-Secure SSH Server for Windows versions prior to 5.3 build 35, update to version 5.3 build 35 or later. For F-Secure SSH Server for UNIX versions 3.0 through 5.0.8, update to a version later than 5.0.8. For SSH Tectia Server versions prior to 4.3.7, update to version 4.3.7 or later. For SSH Shell Server versions prior to 3.2.9, update to version 3.2.9 or later.

Correção

Use of Externally-Controlled Format String

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09523
CVE-2006-0705

Produtos afetados

Attachmatewrq Reflection For Secure It Unix Server
Attachmatewrq Reflection For Secure It Windows Server
F-Secure Ssh Server For Unix
F-Secure Ssh Server For Windows
Ssh Shell Server
Ssh Tectia Server