AttachmateWRQ Reflection for Secure IT Remote Format String Vulnerability
BID:16625
Info
AttachmateWRQ Reflection for Secure IT Remote Format String Vulnerability
| Bugtraq ID: | 16625 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2006 12:00AM |
| Updated: | Feb 14 2006 09:18PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
F-Secure SSH Server 3.1 .0 build 9 F-Secure SSH Server 3.1 .0 F-Secure SSH Server 3.0.9 F-Secure SSH Server 3.0.8 F-Secure SSH Server 3.0.7 F-Secure SSH Server 3.0.6 F-Secure SSH Server 3.0.5 F-Secure SSH Server 3.0.4 F-Secure SSH Server 3.0.3 F-Secure SSH Server 3.0.2 F-Secure SSH Server 3.0.1 F-Secure SSH Server 3.0 .0 F-Secure SSH Server 5.0 F-Secure SSH 5.3 For Windows F-Secure SSH 5.2 For Windows F-Secure SSH 5.1 For Windows F-Secure SSH 3.2.3 For UNIX F-Secure SSH 3.2 .0 For UNIX F-Secure SSH 3.1 .0 For UNIX F-Secure SSH 3.0.1 For UNIX AttachmateWRQ Reflection for Secure IT 6.0 |
| Not Vulnerable: | |
Discussion
AttachmateWRQ Reflection for Secure IT Remote Format String Vulnerability
A remote format-string vulnerability affects AttachmateWRQ Reflection for Secure IT. The application fails to properly sanitize user-supplied input data before using it in a formatted-printing function.
A remote attacker may leverage this issue to execute arbitrary machine code, possibly allowing for privilege escalation and for the bypassing of SFTP-only access controls on affected SSH servers. Attackers may also cause a denial-of-service condition against the affected SSH server.
A remote format-string vulnerability affects AttachmateWRQ Reflection for Secure IT. The application fails to properly sanitize user-supplied input data before using it in a formatted-printing function.
A remote attacker may leverage this issue to execute arbitrary machine code, possibly allowing for privilege escalation and for the bypassing of SFTP-only access controls on affected SSH servers. Attackers may also cause a denial-of-service condition against the affected SSH server.
Exploit / POC
AttachmateWRQ Reflection for Secure IT Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
AttachmateWRQ Reflection for Secure IT Remote Format String Vulnerability
Solution:
The vendor has released an advisory along with fixes to address this issue. Please see the referenced advisory for further information on obtaining fixes.
Solution:
The vendor has released an advisory along with fixes to address this issue. Please see the referenced advisory for further information on obtaining fixes.
References
AttachmateWRQ Reflection for Secure IT Remote Format String Vulnerability
References:
References: