PT-2008-1751 · Georgia Softworks · Georgia Softworks Ssh2 Server
Luigi Auriemma
·
Published
2008-01-08
·
Updated
2018-10-15
·
CVE-2008-0096
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Georgia SoftWorks SSH2 Server (GSW SSHD) versions 7.01.0003 and earlier
Description
The issue is related to multiple buffer overflows that allow remote attackers to execute arbitrary code. This can be achieved by providing a long
username, which triggers an overflow in the log function, or by using a long password.Recommendations
For Georgia SoftWorks SSH2 Server (GSW SSHD) versions 7.01.0003 and earlier, consider updating to a version that is not affected by this issue. As a temporary workaround, restrict access to the SSH2 server to minimize the risk of exploitation. Avoid using long usernames or passwords in the affected server until the issue is resolved.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Georgia Softworks Ssh2 Server