PT-2006-5124 · Ssh+1 · Ssh Tectia Client/Server/Connector+3
Published
2006-08-23
·
Updated
2017-07-20
·
CVE-2006-4315
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SSH Tectia Client/Server/Connector versions 5.0.0 through 5.0.1
SSH Tectia Client/Server versions prior to 4.4.5
SSH Tectia Manager versions prior to 2.12
Description
The issue is related to an unquoted Windows search path vulnerability in SSH Tectia products when running on Windows. This might allow local users to gain privileges via a malicious program file under "Program Files" or its subdirectories.
Recommendations
For SSH Tectia Client/Server/Connector versions 5.0.0 through 5.0.1, update to a version later than 5.0.1.
For SSH Tectia Client/Server versions prior to 4.4.5, update to version 4.4.5 or later.
For SSH Tectia Manager versions prior to 2.12, update to version 2.12 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ssh Tectia Client/Server
Ssh Tectia Client/Server/Connector
Ssh Tectia Manager
Windows