SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#477960

WeOnlyDo! Software wodSSHServer ActiveX component fails to properly validate key exchange algorithm strings

Overview

The WeOnlyDo! Software wodSSHServer ActiveX component fails to properly validate the length of key exchange algorithm strings. This may allow a remote, unauthenticated attacker to execute arbitrary code.

I. Description

wodSSHServer ActiveX component

According to the wodSSHServer ActiveX component website:

    wodSSHServer is an SSH Server ActiveX component (but also Telnet Server ActiveX as well) that will give you ability to easily add SSH2 (and SFTP) server capabilities to your application, as well as old TELNET server protocol.
The Problem

wodSSHServer does not validate key exchange algorithm strings supplied by a client. If a client sends a specially crafted key exchange algorithm string to a vulnerable wodSSHServer installation, that attacker may be able to trigger the overflow.

Any application that uses the wodSSHServer ActiveX Component may be affected by this vulnerability. Known instances of this are freeSSHd and freeFTPd, but there may be others.

Note that working exploit code for this vulnerability is publicly available.

II. Impact

A remote attacker may be able to execute arbitrary code on the server using the wodSSHServer ActiveX component. If that server is running with administrative privileges, the attacker could gain complete control of the system.

III. Solution

Upgrade

This issue is addressed in wodSSHServer ActiveX component version 1.3.4, freeSSHd version 1.0.10, and freeFTPd version 1.0.11.

Systems Affected

VendorStatusDate Updated
WeOnlyDo! SoftwareVulnerable18-May-2006

References


http://secunia.com/advisories/19846/
http://secunia.com/advisories/19845/
http://www.weonlydo.com/index.asp?showform=SSHServer&rnotes=1
http://freesshd.com/
http://www.freeftpd.com/

Credit

This issue was reported by Gerry Eisenhaur.

This document was written by Jeff Gennari.

Other Information

Date Public05/12/2006
Date First Published05/18/2006 04:10:36 PM
Date Last Updated05/18/2006
CERT Advisory 
CVE-ID(s)CVE-2006-2407
NVD-ID(s)CVE-2006-2407
US-CERT Technical Alerts 
Metric32.92
Document Revision28

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader