Sysax Multi Server < 5.55 SSH Username Buffer Overflow
Vulnerability Description
Sysax Multi Server versions prior to 5.55 contain a stack-based buffer overflow in its SSH service. When a remote attacker supplies an overly long username during authentication, the server copies the input to a fixed-size stack buffer without proper bounds checking. This allows remote code execution under the context of the service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-10060
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Craig Freyman
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/ssh/sysax_ssh_username.rb
- https://www.exploit-db.com/exploits/18535
- https://www.exploit-db.com/exploits/18557
- https://web.archive.org/web/20120302203344/http://www.pwnag3.com/2012/02/sysax-multi-server-ssh-username-exploit.html
- https://advisories.checkpoint.com/defense/advisories/public/2012/cpai-23-sepc.html
- https://www.sysax.com/
- https://www.vulncheck.com/advisories/sysax-multi-server-ssh-username-buffer-overflow
More from Sysax Software
View All →Affected Vendor
Sysax Software
View all reports →