Release date: 2012-3 3
Updated on:
Affected Systems:
SSH Communications SSH Tectia Server
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56783
SSH Tectia Server is a security solution for system management, file transmission, and application connection network.
SSH Tectia Server has an error in the Code Implementation of ssh userauth change request. attackers can send a password change request to the authorization service without using the password to log on, resulting in authorization bypass.
<* Source: Kingdom (kingcope@gmx.net)
Link: http://eromang.zataz.com/2012/12/02/tectia-ssh-server-authentication-bypass-remote-0day-exploit-demo/
Http://seclists.org/fulldisclosure/2012/Dec/12
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SSH Communications
------------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.ssh.com/