PT-2008-4028 · None · Freesshd

Securfrog

·

Publicado

2008-06-06

·

Atualizado

2018-10-11

·

CVE-2008-2573

CVSS v2.0

8.5

Alta

VetorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions freeSSHd version 1.2.1
Description The issue is a stack-based buffer overflow in the SFTP component of freeSSHd, allowing remote authenticated users to execute arbitrary code. This can be achieved by sending a long directory name in an SSH FXP OPENDIR (also known as opendir) command.
Recommendations For freeSSHd version 1.2.1, consider restricting access to the SFTP component until a patch is available. As a temporary workaround, limit the length of directory names that can be used in SSH FXP OPENDIR commands to prevent exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2573

Produtos afetados

Freesshd