[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-0225Date: (C)2006-01-25   (M)2023-12-22


scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.6
Exploit Score: 3.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1015540
SUNALERT-102961
BID-16369
SECUNIA-18579
SECUNIA-18595
SECUNIA-18650
SECUNIA-18736
SECUNIA-18798
SECUNIA-18850
SECUNIA-18910
SECUNIA-18964
SECUNIA-18969
SECUNIA-18970
SECUNIA-19159
2006-0004
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.8/common/005_ssh.patch
20060703-01-P
SECUNIA-20723
SECUNIA-21129
SECUNIA-21262
SECUNIA-21492
SECUNIA-21724
SECUNIA-22196
OSVDB-22692
SECUNIA-23241
SECUNIA-23340
SECUNIA-23680
SECUNIA-24479
SECUNIA-25607
SECUNIA-25936
SREASON-462
ADV-2006-0306
ADV-2006-2490
ADV-2006-4869
ADV-2007-0930
ADV-2007-2120
APPLE-SA-2007-03-13
FEDORA-2006-056
FLSA-2006:168935
GLSA-200602-11
HPSBUX02178
MDKSA-2006:034
OpenPKG-SA-2006.003
RHSA-2006:0044
RHSA-2006:0298
RHSA-2006:0698
SSA:2006-045-06
SUSE-SA:2006:008
TA07-072A
USN-255-1
http://blogs.sun.com/security/entry/sun_alert_102961_security_vulnerability
http://docs.info.apple.com/article.html?artnum=305214
http://support.avaya.com/elmodocs2/security/ASA-2006-158.htm
http://support.avaya.com/elmodocs2/security/ASA-2006-174.htm
http://support.avaya.com/elmodocs2/security/ASA-2006-262.htm
http://support.avaya.com/elmodocs2/security/ASA-2007-246.htm
http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html
http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html
http://www14.software.ibm.com/webapp/set2/sas/f/hmc/power5/install/v52.Readme.html#MH00688
http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=2751
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174026
openssh-scp-command-execution(24305)
oval:org.mitre.oval:def:1138
oval:org.mitre.oval:def:9962

CPE    33
cpe:/a:openbsd:openssh:3.7.1p2
cpe:/a:openbsd:openssh:3.9.1p1
cpe:/a:openbsd:openssh:3.1
cpe:/a:openbsd:openssh:3.0
...

© SecPod Technologies