PT-2008-4028 · None · Freesshd

Securfrog

·

Published

2008-06-06

·

Updated

2018-10-11

·

CVE-2008-2573

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions freeSSHd version 1.2.1
Description The issue is a stack-based buffer overflow in the SFTP component of freeSSHd, allowing remote authenticated users to execute arbitrary code. This can be achieved by sending a long directory name in an SSH FXP OPENDIR (also known as opendir) command.
Recommendations For freeSSHd version 1.2.1, consider restricting access to the SFTP component until a patch is available. As a temporary workaround, limit the length of directory names that can be used in SSH FXP OPENDIR commands to prevent exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2573

Affected Products

Freesshd