PT-2009-2368 · None · Freesshd

Publicado

2009-08-05

·

Atualizado

2018-10-11

·

CVE-2008-6899

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: freeSSHd version 1.2.1
Description: The issue allows remote authenticated users to cause a denial of service and execute arbitrary code via long SFTP commands, including open, unlink, mkdir, rmdir, or stat commands.
Recommendations: For freeSSHd version 1.2.1, consider restricting access to SFTP commands or updating to a version that addresses these buffer overflows, if available. As a temporary workaround, restrict the length of input for SFTP commands to prevent exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6899

Produtos afetados

Freesshd