Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://securitytracker.com/id?1005812 | vdb entry |
http://www.cert.org/advisories/CA-2002-36.html | third party advisory us government resource |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5721 | signature vdb entry |
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0110.html | mailing list |
http://securitytracker.com/id?1005813 | vdb entry |