PT-2008-1752 · Georgia Softworks · Georgia Softworks Ssh2 Server
Published
2008-01-08
·
Updated
2018-10-15
·
CVE-2008-0097
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Georgia SoftWorks SSH2 Server (GSW SSHD) versions 7.01.0003 and earlier
Description
The issue allows remote attackers to execute arbitrary code via format string specifiers in the
username field. This can be demonstrated by a certain LoginPassword message.Recommendations
For versions 7.01.0003 and earlier, consider disabling the log function temporarily until a patch is available to prevent exploitation. Restrict access to the log function to minimize the risk of arbitrary code execution. Avoid using format string specifiers in the
username field until the issue is resolved.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Georgia Softworks Ssh2 Server