PT-2008-4028 · None · Freesshd
Securfrog
·
Publicado
2008-06-06
·
Atualizado
2018-10-11
·
CVE-2008-2573
CVSS v2.0
8.5
Alta
| Vetor | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
freeSSHd version 1.2.1
Description
The issue is a stack-based buffer overflow in the SFTP component of freeSSHd, allowing remote authenticated users to execute arbitrary code. This can be achieved by sending a long directory name in an SSH FXP OPENDIR (also known as opendir) command.
Recommendations
For freeSSHd version 1.2.1, consider restricting access to the SFTP component until a patch is available. As a temporary workaround, limit the length of directory names that can be used in SSH FXP OPENDIR commands to prevent exploitation.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Freesshd