Overview
The WeOnlyDo! Software wodSSHServer ActiveX component fails to properly validate the length of key exchange algorithm strings. This may allow a remote, unauthenticated attacker to execute arbitrary code.
Description
wodSSHServer ActiveX component According to the wodSSHServer ActiveX component website: |
Impact
A remote attacker may be able to execute arbitrary code on the server using the wodSSHServer ActiveX component. If that server is running with administrative privileges, the attacker could gain complete control of the system. |
Solution
Upgrade This issue is addressed in wodSSHServer ActiveX component version 1.3.4, freeSSHd version 1.0.10, and freeFTPd version 1.0.11. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This issue was reported by Gerry Eisenhaur.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-2407 |
Severity Metric: | 32.92 |
Date Public: | 2006-05-12 |
Date First Published: | 2006-05-18 |
Date Last Updated: | 2006-05-18 21:49 UTC |
Document Revision: | 30 |