DoS in Bitvise WinSSH for Windows 2000

Reported March 16, 2002, by Peter Gründl.

VERSION AFFECTED

  • Bitvise WinSSH for Windows 2000

DESCRIPTION
When a user logs on to his or her account through the IMail Server Web interface, the application uses a unique URL to maintain the session authentication. A vulnerability exists in Bitvise’s WinSSH that can result in a Denial of Service (DoS) condition. Because of differences in the Secure Shell (SSH) daemon and the underlying socket layer, an attacker can abruptly end sessions without SSH properly freeing those sessions. Each incomplete connection would use a few memory handles and allocate nonpaged kernel memory.


VENDOR RESPONSE

The vendor, Bitvise, has released a new build that this condition doesn't affect. The company recommends that affected users download this updated version from http://www.bitvise.com/existing-users.html.


CREDIT
Discovered by Peter Gründl.

TAGS: Security
Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish