kb.cert.org

Overview

A logging function used by multiple vendors' SFTP servers contains a format string vulnerability, which may allow an authorized remote attacker to execute arbitrary code or cause a denial of service.

Description

SFTP

SFTP (Secure FTP) is a file transfer application that uses SSH for encryption.

The problem

The logging function of several vendors' SFTP servers contains a format string vulnerability.

Vulnerable products include:

    • Reflection for Secure IT UNIX Server version 6.0
    • Reflection for Secure IT Windows Server version 6.0
    • F-Secure SSH Server for Windows version 5.x
    • F-Secure SSH Server for UNIX version 3.x through 5.x

Impact

A remote authenticated attacker may be able to execute arbitrary code with the privilege of the user or cause a denial of service to the SSH server.

Solution

Upgrade or patch


AttachmateWRQ Reflection for Secure IT and F-Secure SSH Server users should install an upgrade, as specified in WRQ Tech Note 1882.

According to the WRQ Tech note, the following workaround may prevent exploitation of the vulnerability:

On UNIX Servers    1. Edit the SSH server's sshd2_config file:          1. Change the line             subsystem-sftp internal://sftp-server             to             subsystem-sftp sftp-server             Note:  This change disallows the use of chroot.          2. Comment out the SftpSyslogFacility keyword line. Note:  The line should begin with two "pound" signs, as in this example:             ## SftpSyslogFacility LOCAL7    2. Restart the SSH server to read the changes in the configuration file. On Windows Servers
The only workaround is to disable the sftp subsystem as follows:    1. Edit the SSH server's sshd2_config file and comment out the subsystem-sftp line. Note:  The line should begin with two "pound" signs, as in this example:             ## subsystem-sftp "fsshsftpd.exe"    2. Restart the SSH server to read the change in the configuration file.

Vendor Information

419241

Filter by status:

Filter by content: Additional information available

 Sort by:


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to WRQ for reporting this vulnerability.

This document was written by Will Dormann.

Other Information

CVE IDs: None
Severity Metric: 3.38
Date Public: 2006-02-13
Date First Published: 2006-02-13
Date Last Updated: 2006-02-15 14:51 UTC
Document Revision: 10

Read the original on kb.cert.org ↗