Tracker / CVE-2002-1360
CVE-2002-1360
Alta 10.0
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.
Prodotti e versioni affette
| cisco | ios |
|---|---|
| fissh | ssh_client |
| intersoft | securenetterm |
| netcomposite | shellguard_ssh |
| pragma_systems | secureshell |
| putty | putty |
| winscp | winscp |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.