PT-2002-2065 · Vandyke · Securecrt
Published
2002-10-04
·
Updated
2016-10-18
·
CVE-2002-1059
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Van Dyke SecureCRT SSH client versions prior to 3.4.6
Van Dyke SecureCRT SSH client versions 4.x prior to 4.0 beta 3
Description:
The issue allows an SSH server to execute arbitrary code via a long SSH1 protocol version string. This is due to a buffer overflow in the Van Dyke SecureCRT SSH client.
Recommendations:
For versions prior to 3.4.6, update to version 3.4.6 or later.
For versions 4.x prior to 4.0 beta 3, update to version 4.0 beta 3 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Securecrt