Reported March 16, 2002, by Peter Gründl.
VERSION AFFECTED
Bitvise WinSSH for Windows 2000
DESCRIPTION
VENDOR RESPONSE
The vendor, Bitvise, has released a new build that this condition doesn't affect. The company recommends that affected users download this updated version from http://www.bitvise.com/existing-users.html.
CREDIT
When a user logs on to his or her account through the IMail Server Web interface, the application uses a unique URL to maintain the session authentication.
A vulnerability exists in Bitvise’s WinSSH that can result in a Denial of Service (DoS) condition. Because of differences in the Secure Shell (SSH) daemon and the underlying socket layer, an attacker can abruptly end sessions without SSH properly freeing those sessions. Each incomplete connection would use a few memory handles and allocate nonpaged kernel memory.
Discovered by Peter Gründl.
DoS in Bitvise WinSSH for Windows 2000
0 comments
Hide comments