CVE-2006-2407
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 71.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange algorithm string.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 71.38% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- freeftpd/freeftpd · freesshd/freesshd · weonlydo/wodsshserver
- Source
- cve@mitre.org
References
- http://marc.info/?l=full-disclosure&m=114764338702488&w=2
- http://secunia.com/advisories/19845Patch, Vendor Advisory
- http://secunia.com/advisories/19846Vendor Advisory
- http://secunia.com/advisories/20136Vendor Advisory
- http://securityreason.com/securityalert/901
- http://www.kb.cert.org/vuls/id/477960US Government Resource
- http://www.osvdb.org/25463
- http://www.osvdb.org/25569
- http://www.securityfocus.com/archive/1/434007/100/0/threaded
- http://www.securityfocus.com/archive/1/434038/100/0/threaded
- http://www.securityfocus.com/archive/1/434402/100/0/threaded
- http://www.securityfocus.com/archive/1/434415/100/0/threaded
- http://www.securityfocus.com/archive/1/434415/30/4920/threaded
- http://www.securityfocus.com/bid/17958Exploit
- http://www.vupen.com/english/advisories/2006/1785Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1786Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1842Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26442
- http://marc.info/?l=full-disclosure&m=114764338702488&w=2
- http://secunia.com/advisories/19845Patch, Vendor Advisory
- http://secunia.com/advisories/19846Vendor Advisory
- http://secunia.com/advisories/20136Vendor Advisory
- http://securityreason.com/securityalert/901
- http://www.kb.cert.org/vuls/id/477960US Government Resource
- http://www.osvdb.org/25463
- http://www.osvdb.org/25569
- http://www.securityfocus.com/archive/1/434007/100/0/threaded
- http://www.securityfocus.com/archive/1/434038/100/0/threaded
- http://www.securityfocus.com/archive/1/434402/100/0/threaded
- http://www.securityfocus.com/archive/1/434415/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.