PT-2008-1752 · Georgia Softworks · Georgia Softworks Ssh2 Server
Publicado
2008-01-08
·
Atualizado
2018-10-15
·
CVE-2008-0097
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Georgia SoftWorks SSH2 Server (GSW SSHD) versions 7.01.0003 and earlier
Description
The issue allows remote attackers to execute arbitrary code via format string specifiers in the
username field. This can be demonstrated by a certain LoginPassword message.Recommendations
For versions 7.01.0003 and earlier, consider disabling the log function temporarily until a patch is available to prevent exploitation. Restrict access to the log function to minimize the risk of arbitrary code execution. Avoid using format string specifiers in the
username field until the issue is resolved.Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Georgia Softworks Ssh2 Server