SSH Tectia Client and Server ssh-signer Local Privilege Escalation Vulnerability
BID:27191
Info
SSH Tectia Client and Server ssh-signer Local Privilege Escalation Vulnerability
| Bugtraq ID: | 27191 |
| Class: | Design Error |
| CVE: |
CVE-2007-5616 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 08 2008 12:00AM |
| Updated: | Jan 10 2008 06:49PM |
| Credit: | Tuomas Siren reported this issue. |
| Vulnerable: |
SSH Communications Security SSH Tectia 5.3.5 SSH Communications Security SSH Tectia 5.2.3 SSH Communications Security SSH Tectia 5.1.1 SSH Communications Security SSH Tectia 5.3 SSH Communications Security SSH Tectia 5.2 SSH Communications Security SSH Tectia 5.1 SSH Communications Security SSH Tectia 5.0 |
| Not Vulnerable: |
SSH Communications Security SSH Tectia 5.3.6 SSH Communications Security SSH Tectia 5.2.4 |
Discussion
SSH Tectia Client and Server ssh-signer Local Privilege Escalation Vulnerability
SSH Tectia Client and Server software running on UNIX operating systems is prone to a local privilege-escalation vulnerability.
Successful exploits allow local attackers to gain superuser-level access to affected computers. This facilitates the complete compromise of affected computers.
This issue affects these versions:
SSH Tectia Client/Server 5.0 through 5.2.3
SSH Tectia Client/Server 5.3 through 5.3.5.
This issue affects only UNIX-based platforms.
SSH Tectia Client and Server software running on UNIX operating systems is prone to a local privilege-escalation vulnerability.
Successful exploits allow local attackers to gain superuser-level access to affected computers. This facilitates the complete compromise of affected computers.
This issue affects these versions:
SSH Tectia Client/Server 5.0 through 5.2.3
SSH Tectia Client/Server 5.3 through 5.3.5.
This issue affects only UNIX-based platforms.
Exploit / POC
Solution / Fix
References
SSH Tectia Client and Server ssh-signer Local Privilege Escalation Vulnerability
References:
References:
- SSH Tectia Client and SSH Tectia Server Product Page (SSH)
- Vendor Homepage (SSH Communications Security)
- Vulnerability Note VU#921339 (US-CERT)