Debian openssh-server Forced Command Handling Information Disclosure Vulnerability
BID:51702
Info
Debian openssh-server Forced Command Handling Information Disclosure Vulnerability
| Bugtraq ID: | 51702 |
| Class: | Design Error |
| CVE: |
CVE-2012-0814 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2012 12:00AM |
| Updated: | May 12 2015 07:46PM |
| Credit: | Bjoern Buerger |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 93.E0.21C Xerox FreeFlow Print Server (FFPS) 91.D2.32 Xerox FreeFlow Print Server (FFPS) 82.D1.44 Xerox FreeFlow Print Server (FFPS) 81.D0.73 Xerox FreeFlow Print Server (FFPS) 73.D2.33 Xerox FreeFlow Print Server (FFPS) 73.C5.11 Oracle Solaris 9 Oracle Solaris 11.1 Oracle Solaris 10 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Juniper IDP 5.1 IBM System x Integrated Management Module (IMM2) 2 IBM Flex System Manager 0 IBM Flex System Integrated Management Module (IMM2) 2 IBM Flex System Chassis Management Module (CMM) 0 IBM BladeCenter Advanced Management Module (AMM) 0 Gentoo Linux EMC VPLEX GeoSynchrony 5.2.1 EMC VPLEX GeoSynchrony 5.2 SP1 EMC VPLEX GeoSynchrony 4.0 Debian openssh-server 1:5.5p1-6+squeeze1 Avaya 96x1 IP Deskphone 6.2 Avaya 96x1 IP Deskphone 6 |
| Not Vulnerable: |
Oracle Solaris 11.1.7.5.0 Juniper IDP 5.1r4 EMC VPLEX GeoSynchrony 5.3 |
Discussion
Debian openssh-server Forced Command Handling Information Disclosure Vulnerability
The Debian openssh-server package is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to gain access to sensitive information; this may lead to further attacks.
Debian openssh-server 1:5.5p1-6+squeeze1 is affected; other versions may also be vulnerable.
The Debian openssh-server package is prone to an information-disclosure vulnerability.
Successful exploits will allow attackers to gain access to sensitive information; this may lead to further attacks.
Debian openssh-server 1:5.5p1-6+squeeze1 is affected; other versions may also be vulnerable.
Exploit / POC
Debian openssh-server Forced Command Handling Information Disclosure Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Debian openssh-server Forced Command Handling Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Debian openssh-server Forced Command Handling Information Disclosure Vulnerability
References:
References: