PT-2008-1751 · Georgia Softworks · Georgia Softworks Ssh2 Server

Luigi Auriemma

·

Published

2008-01-08

·

Updated

2018-10-15

·

CVE-2008-0096

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Georgia SoftWorks SSH2 Server (GSW SSHD) versions 7.01.0003 and earlier
Description The issue is related to multiple buffer overflows that allow remote attackers to execute arbitrary code. This can be achieved by providing a long username, which triggers an overflow in the log function, or by using a long password.
Recommendations For Georgia SoftWorks SSH2 Server (GSW SSHD) versions 7.01.0003 and earlier, consider updating to a version that is not affected by this issue. As a temporary workaround, restrict access to the SSH2 server to minimize the risk of exploitation. Avoid using long usernames or passwords in the affected server until the issue is resolved.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0096

Affected Products

Georgia Softworks Ssh2 Server