PT-2008-1752 · Georgia Softworks · Georgia Softworks Ssh2 Server

Publicado

2008-01-08

·

Atualizado

2018-10-15

·

CVE-2008-0097

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Georgia SoftWorks SSH2 Server (GSW SSHD) versions 7.01.0003 and earlier
Description The issue allows remote attackers to execute arbitrary code via format string specifiers in the username field. This can be demonstrated by a certain LoginPassword message.
Recommendations For versions 7.01.0003 and earlier, consider disabling the log function temporarily until a patch is available to prevent exploitation. Restrict access to the log function to minimize the risk of arbitrary code execution. Avoid using format string specifiers in the username field until the issue is resolved.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0097

Produtos afetados

Georgia Softworks Ssh2 Server