PT-2006-5124 · Ssh+1 · Ssh Tectia Client/Server/Connector+3
Publicado
2006-08-23
·
Atualizado
2017-07-20
·
CVE-2006-4315
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SSH Tectia Client/Server/Connector versions 5.0.0 through 5.0.1
SSH Tectia Client/Server versions prior to 4.4.5
SSH Tectia Manager versions prior to 2.12
Description
The issue is related to an unquoted Windows search path vulnerability in SSH Tectia products when running on Windows. This might allow local users to gain privileges via a malicious program file under "Program Files" or its subdirectories.
Recommendations
For SSH Tectia Client/Server/Connector versions 5.0.0 through 5.0.1, update to a version later than 5.0.1.
For SSH Tectia Client/Server versions prior to 4.4.5, update to version 4.4.5 or later.
For SSH Tectia Manager versions prior to 2.12, update to version 2.12 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ssh Tectia Client/Server
Ssh Tectia Client/Server/Connector
Ssh Tectia Manager
Windows