>> WRQ Reflection for Secure IT Server SFTP Format String Vulnerability
Title : WRQ Reflection for Secure IT Server SFTP Format String Vulnerability VUPEN ID : VUPEN/ADV-2006-0555 CVE ID : CVE-2006-0705
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-02-13
Technical Description
A vulnerability has been identified in Reflection for Secure IT and F-Secure SSH Servers, which could be exploited by attackers to execute arbitrary commands or cause a denial of service. This flaw is due to a format string error in the SFTP logging functionality that fails to properly handle a specially crafted name file, which could be exploited by malicious users to cause a denial of service or by remote unauthenticated attackers to compromise a vulnerable server by convincing a user to "stat" a malicious file.