AttachmateWRQ Reflection for Secure IT Windows Server Insecure Private Key Permissions Vulnerability
BID:14734
Info
AttachmateWRQ Reflection for Secure IT Windows Server Insecure Private Key Permissions Vulnerability
| Bugtraq ID: | 14734 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 25 2005 12:00AM |
| Updated: | Aug 25 2005 12:00AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
F-Secure SSH Server 3.1 .0 build 9 F-Secure SSH Server 3.1 .0 F-Secure SSH Server 3.0.9 F-Secure SSH Server 3.0.8 F-Secure SSH Server 3.0.7 F-Secure SSH Server 3.0.6 F-Secure SSH Server 3.0.5 F-Secure SSH Server 3.0.4 F-Secure SSH Server 3.0.3 F-Secure SSH Server 3.0.2 F-Secure SSH Server 3.0.1 F-Secure SSH Server 3.0 .0 F-Secure SSH 5.3 For Windows F-Secure SSH 5.2 For Windows F-Secure SSH 5.1 For Windows AttachmateWRQ Reflection for Secure IT 6.0 |
| Not Vulnerable: | |
Discussion
AttachmateWRQ Reflection for Secure IT Windows Server Insecure Private Key Permissions Vulnerability
AttachmateWRQ Reflection for Secure IT Windows Server is susceptible to an insecure private key permissions vulnerability. This issue is due to a failure of the application to ensure secure permissions are placed on security-sensitive files.
This issue allows local users to gain access to the contents of private SSH host keys files. This allows attackers to create rouge SSH servers that seem to clients to be identical to the originating server. Man in the middle attacks, gaining access to the contents of encrypted communications, and other attacks are likely possible.
All versions of F-Secure SSH Server for Windows, and AttachmateWRQ Reflection for Secure IT Windows Server version 6.0 are vulnerable to this issue.
AttachmateWRQ Reflection for Secure IT Windows Server is susceptible to an insecure private key permissions vulnerability. This issue is due to a failure of the application to ensure secure permissions are placed on security-sensitive files.
This issue allows local users to gain access to the contents of private SSH host keys files. This allows attackers to create rouge SSH servers that seem to clients to be identical to the originating server. Man in the middle attacks, gaining access to the contents of encrypted communications, and other attacks are likely possible.
All versions of F-Secure SSH Server for Windows, and AttachmateWRQ Reflection for Secure IT Windows Server version 6.0 are vulnerable to this issue.
Exploit / POC
AttachmateWRQ Reflection for Secure IT Windows Server Insecure Private Key Permissions Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
AttachmateWRQ Reflection for Secure IT Windows Server Insecure Private Key Permissions Vulnerability
Solution:
The vendor has released an advisory to address this issue. The advisory details the steps required to resolve this issue. Please see the referenced advisory for further information.
An upgraded version of the affected software is also available from:
https://download.wrq.com/Upgrades/DownloadAgreement.aspx?code=RSSW
Solution:
The vendor has released an advisory to address this issue. The advisory details the steps required to resolve this issue. Please see the referenced advisory for further information.
An upgraded version of the affected software is also available from:
https://download.wrq.com/Upgrades/DownloadAgreement.aspx?code=RSSW
References
AttachmateWRQ Reflection for Secure IT Windows Server Insecure Private Key Permissions Vulnerability
References:
References: