Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server prior to 6.0.0.9, (2) Reflection for Secure IT Windows Server prior to 6.0 build 38, (3) F-Secure SSH Server for Windows prior to 5.3 build 35, (4) F-Secure SSH Server for UNIX 3.0 up to and including 5.0.8, (5) SSH Tectia Server 4.3.6 and previous versions and 4.4.0, and (6) SSH Shell Server 3.2.9 and previous versions, allows remote authenticated users to execute arbitrary commands via unspecified vectors, involving crafted filenames and the stat command.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
attachmatewrq reflection for secure it server 6.0 |
||
f-secure f-secure ssh server 3.0.0 |
||
f-secure f-secure ssh server 3.0.6 |
||
f-secure f-secure ssh server 3.0.7 |
||
f-secure f-secure ssh server 3.2.3 |
||
f-secure f-secure ssh server 5.0 |
||
f-secure f-secure ssh server 3.0.1 |
||
f-secure f-secure ssh server 3.0.8 |
||
f-secure f-secure ssh server 3.0.9 |
||
f-secure f-secure ssh server 5.1 |
||
f-secure f-secure ssh server 5.2 |
||
f-secure f-secure ssh server 3.0.2 |
||
f-secure f-secure ssh server 3.0.3 |
||
f-secure f-secure ssh server 3.1.0 |
||
f-secure f-secure ssh server 5.3 |
||
f-secure f-secure ssh server 3.0.4 |
||
f-secure f-secure ssh server 3.0.5 |
||
f-secure f-secure ssh server 3.1.0_build9 |
||
f-secure f-secure ssh server 3.2.0 |