SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#419241

Multiple vendor SFTP logging format string vulnerability

Overview

A logging function used by multiple vendors' SFTP servers contains a format string vulnerability, which may allow an authorized remote attacker to execute arbitrary code or cause a denial of service.

I. Description

SFTP

SFTP (Secure FTP) is a file transfer application that uses SSH for encryption.

The problem

The logging function of several vendors' SFTP servers contains a format string vulnerability.

Vulnerable products include:

  • Reflection for Secure IT UNIX Server version 6.0
  • Reflection for Secure IT Windows Server version 6.0
  • F-Secure SSH Server for Windows version 5.x
  • F-Secure SSH Server for UNIX version 3.x through 5.x

II. Impact

A remote authenticated attacker may be able to execute arbitrary code with the privilege of the user or cause a denial of service to the SSH server.

III. Solution

Upgrade or patch


AttachmateWRQ Reflection for Secure IT and F-Secure SSH Server users should install an upgrade, as specified in WRQ Tech Note 1882.


According to the WRQ Tech note, the following workaround may prevent exploitation of the vulnerability:

    On UNIX Servers

       1. Edit the SSH server's sshd2_config file:

             1. Change the line

                subsystem-sftp internal://sftp-server

                to

                subsystem-sftp sftp-server

                Note: This change disallows the use of chroot.

             2. Comment out the SftpSyslogFacility keyword line. Note: The line should begin with two "pound" signs, as in this example:

                ## SftpSyslogFacility LOCAL7

       2. Restart the SSH server to read the changes in the configuration file.

    On Windows Servers
    The only workaround is to disable the sftp subsystem as follows:

       1. Edit the SSH server's sshd2_config file and comment out the subsystem-sftp line. Note: The line should begin with two "pound" signs, as in this example:

                ## subsystem-sftp "fsshsftpd.exe"

       2. Restart the SSH server to read the change in the configuration file.

    Systems Affected

    VendorStatusDate Updated
    BitviseNot Vulnerable17-Jan-2006
    F-Secure CorporationVulnerable15-Feb-2006
    FiSSHUnknown16-Jan-2006
    InterSoft InternationalNot Vulnerable18-Jan-2006
    lshUnknown16-Jan-2006
    MacSSHNot Vulnerable16-Jan-2006
    OpenSSHUnknown16-Jan-2006
    OSSHNot Vulnerable16-Jan-2006
    Pragma SystemsUnknown16-Jan-2006
    PuTTYNot Vulnerable16-Jan-2006
    TTSSHUnknown16-Jan-2006
    VanDyke SoftwareNot Vulnerable17-Jan-2006
    WinSCPUnknown16-Jan-2006
    WRQ, Inc.Vulnerable15-Feb-2006

    References



http://support.wrq.com/techdocs/1882.html

Credit

Thanks to WRQ for reporting this vulnerability.

This document was written by Will Dormann.

Other Information

Date Public02/13/2006
Date First Published02/13/2006 04:20:30 PM
Date Last Updated02/15/2006
CERT Advisory 
CVE-ID(s) 
NVD-ID(s) 
US-CERT Technical Alerts 
Metric3.37
Document Revision9

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader