>> SSH Tectia Server SFTP Logging Function Format String Vulnerability
Title : SSH Tectia Server SFTP Logging Function Format String Vulnerability VUPEN ID : VUPEN/ADV-2006-0554 CVE ID : GENERIC-MAP-NOMATCH
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-02-13
Technical Description
A vulnerability has been identified in SSH Tectia Server, which could be exploited by attackers to execute arbitrary commands or cause a denial of service. This flaw is due to a format string error in the SFTP logging functionality that fails to properly handle a specially crafted name file, which could be exploited by malicious users to cause a denial of service or by remote unauthenticated attackers to compromise a vulnerable server by convincing a user to "stat" a malicious file.