CVE-2006-0705
Summary
| CVE | CVE-2006-0705 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-02-15 11:06:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3 build 35, (4) F-Secure SSH Server for UNIX 3.0 through 5.0.8, (5) SSH Tectia Server 4.3.6 and earlier and 4.4.0, and (6) SSH Shell Server 3.2.9 and earlier, allows remote authenticated users to execute arbitrary commands via unspecified vectors, involving crafted filenames and the stat command. |
Risk And Classification
Primary CVSS: v2.0 6.5 from [email protected]
AV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS: 0.101880000 probability, percentile 0.951580000 (date 2026-07-21)
Problem Types: CWE-134 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Attachmatewrq | Reflection For Secure It Server | 6.0 | All | unix | All |
| Application | Attachmatewrq | Reflection For Secure It Server | 6.0 | All | win | All |
| Application | F-secure | F-secure Ssh Server | 3.0.0 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 3.0.1 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 3.0.1 | All | unix | All |
| Application | F-secure | F-secure Ssh Server | 3.0.2 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 3.0.3 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 3.0.4 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 3.0.5 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 3.0.6 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 3.0.7 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 3.0.8 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 3.0.9 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 3.1.0 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 3.1.0 | All | unix | All |
| Application | F-secure | F-secure Ssh Server | 3.1.0_build9 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 3.2.0 | All | unix | All |
| Application | F-secure | F-secure Ssh Server | 3.2.3 | All | unix | All |
| Application | F-secure | F-secure Ssh Server | 5.0 | All | All | All |
| Application | F-secure | F-secure Ssh Server | 5.1 | All | win | All |
| Application | F-secure | F-secure Ssh Server | 5.2 | All | win | All |
| Application | F-secure | F-secure Ssh Server | 5.3 | All | win | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WRQ Reflection Secure IT SFTP Format String Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| SSH Tectia Server SFTP Service Unspecified Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| marc.info | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityTracker.com Archives - SSH Tectia Server SFTP Logging Bug May Let Remote Authenticated Users Execute Arbitrary Commands | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| US-CERT Vulnerability Note VU#419241 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Patch, US Government Resource |
| SSH Communications Security's Secure Shell Server: SFTP privilege escalation — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| SSH Tectia Server Remote Format String Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| AttachmateWRQ Reflection for Secure IT Remote Format String Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| WRQ Tech Note 1882 - Reflection for Secure IT Server Security Vulnerability Update and Workaround | af854a3a-2127-422b-91ae-364da2661108 | support.wrq.com | Patch |
| Gentoo net-misc/ssh Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| HP Tru64 UNIX SSH SFTP Server Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.