|
|
| |
|
| |
ssh: privilege escalation
| Package(s): | ssh |
CVE #(s): | CVE-2006-0705
|
| Created: | March 15, 2007 |
Updated: | March 21, 2007 |
| Description: |
The SSH server has a format string vulnerability in
the SFTP code for scp2 and sftp2. The accessed filename can be passed
to the system log, an unspecified error could allow uncontrolled
stack access. Authenticated users may be able to use this to
bypass command restrictions or run commands as another user. |
| Alerts: |
|
( Log in to post comments)
|
|
|