PT-2008-5937 · Goodtech · Goodtech Ssh

R0Ut3R

·

Published

2008-10-23

·

Updated

2018-10-11

·

CVE-2008-4726

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GoodTech SSH version 6.4
Description The issue is a stack-based buffer overflow in the SFTP subsystem. This can be exploited by remote authenticated users who send a long string to certain parameters, including the open (also known as SSH FXP OPEN), unlink, and opendir parameters, allowing them to execute arbitrary code.
Recommendations For GoodTech SSH version 6.4, consider restricting access to the SFTP subsystem until a patch is available. As a temporary workaround, avoid using long strings in the open, unlink, and opendir parameters to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4726

Affected Products

Goodtech Ssh