Overview
SecureCRT is vulnerable to buffer overflow from improper handling of long password input.
Description
SecureCRT is a terminal emulator and SSH client for Windows. If the SSH1 protocol is used and the user enters a password 300 characters or more in length, SecureCRT will crash, with the following error displayed by Windows: "SECURECRT caused an invalid page fault in module MSVCRT.DLL..." |
Impact
Local users may be able to execute arbitrary code on the client host by supplying a long password to SecureCRT. |
Solution
The CERT/CC is currently unaware of a practical solution to this problem. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Blackshell Security Advisory for reporting this vulnerability.
This document was written by Shawn Van Ittersum.
Other Information
CVE IDs: | None |
Severity Metric: | 0.06 |
Date Public: | 2001-12-30 |
Date First Published: | 2002-09-16 |
Date Last Updated: | 2003-04-15 14:01 UTC |
Document Revision: | 11 |