SSH Tectia Server Remote Format String Vulnerability
BID:16640
Info
SSH Tectia Server Remote Format String Vulnerability
| Bugtraq ID: | 16640 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0705 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2006 12:00AM |
| Updated: | Dec 01 2008 11:52PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
SSH Communications Security Tectia Server 4.4 SSH Communications Security Tectia Server 4.3.6 SSH Communications Security Tectia Server 4.3.5 SSH Communications Security Tectia Server 4.3.4 SSH Communications Security Tectia Server 4.3.3 SSH Communications Security Tectia Server 4.3.2 SSH Communications Security Tectia Server 4.3.1 SSH Communications Security Tectia Server 4.3 SSH Communications Security Tectia Server 4.2.1 SSH Communications Security Tectia Server 4.0.5 SSH Communications Security Tectia Server 4.0.4 SSH Communications Security Tectia Server 4.0.3 SSH Communications Security Tectia Server 4.0 SSH Communications Security Tectia Server 4.1 SSH Communications Security SSH2 for Win32 3.1.2 SSH Communications Security SSH2 for Win32 3.1.1 SSH Communications Security SSH2 for Win32 3.1 SSH Communications Security SSH2 for Unix 3.2.2 SSH Communications Security SSH2 for Unix 3.1.2 SSH Communications Security SSH2 for Unix 3.1.1 SSH Communications Security SSH2 for Unix 3.1 SSH Communications Security SSH2 3.2.9 SSH Communications Security SSH2 3.2.5 SSH Communications Security SSH2 3.2.4 SSH Communications Security SSH2 3.2.3 SSH Communications Security SSH2 3.2.2 SSH Communications Security SSH2 3.2.1 SSH Communications Security SSH2 3.2 SSH Communications Security SSH2 3.1.8 SSH Communications Security SSH2 3.1.7 SSH Communications Security SSH2 3.1.6 SSH Communications Security SSH2 3.1.5 SSH Communications Security SSH2 3.1.4 SSH Communications Security SSH2 3.1.3 SSH Communications Security SSH2 3.1.2 SSH Communications Security SSH2 3.1.1 SSH Communications Security SSH2 3.1 SSH Communications Security SSH2 3.0.1 SSH Communications Security SSH2 3.0 SSH Communications Security SSH2 2.5 SSH Communications Security SSH2 2.4 SSH Communications Security SSH2 2.3 SSH Communications Security SSH2 2.2 SSH Communications Security SSH2 2.1 SSH Communications Security SSH2 2.0.13 SSH Communications Security SSH2 2.0.12 SSH Communications Security SSH2 2.0.11 SSH Communications Security SSH2 2.0.10 SSH Communications Security SSH2 2.0.9 SSH Communications Security SSH2 2.0.8 SSH Communications Security SSH2 2.0.7 SSH Communications Security SSH2 2.0.6 SSH Communications Security SSH2 2.0.5 SSH Communications Security SSH2 2.0.4 SSH Communications Security SSH2 2.0.3 SSH Communications Security SSH2 2.0.2 SSH Communications Security SSH2 2.0.1 SSH Communications Security SSH2 2.0 HP Tru64 UNIX 5.1.0 B-4 HP Tru64 UNIX 5.1.0 B-3 HP Tru64 5.1 B-4 HP Tru64 5.1 B-3 Gentoo Linux |
| Not Vulnerable: |
SSH Communications Security Tectia Server 4.4.2 SSH Communications Security Tectia Server 4.3.7 |
Discussion
SSH Tectia Server Remote Format String Vulnerability
A remote format-string vulnerability affects SSH Tectia Server. The application fails to properly sanitize user-supplied input data before using it in a formatted-printing function.
A remote attacker may leverage this issue to execute arbitrary machine code, possibly allowing for privilege escalation and for the bypassing of SFTP-only access controls on affected SSH servers.
A remote format-string vulnerability affects SSH Tectia Server. The application fails to properly sanitize user-supplied input data before using it in a formatted-printing function.
A remote attacker may leverage this issue to execute arbitrary machine code, possibly allowing for privilege escalation and for the bypassing of SFTP-only access controls on affected SSH servers.
Exploit / POC
SSH Tectia Server Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SSH Tectia Server Remote Format String Vulnerability
Solution:
The vendor has released an advisory along with fixes to address this issue. Please see the referenced advisory for information on obtaining fixes.
Solution:
The vendor has released an advisory along with fixes to address this issue. Please see the referenced advisory for information on obtaining fixes.
References
SSH Tectia Server Remote Format String Vulnerability
References:
References:
- SSH Tectia Server 4.3/4.4 SFTP Vulnerability (SSH Communications Security)
- SSH Tectia Server Product Page (SSH Communications Security)