Security Advisory—CRT™ and SecureCRT® 4.0, 4.1 |
||||||||||||||||||||
VanDyke Software has released CRT 4.1.9 and SecureCRT 4.1.9 to eliminate a security issue in CRT and SecureCRT 4.0 and 4.1. When launching CRT or SecureCRT from a URL, if CRT or SecureCRT was selected as the default Telnet client, it was possible to run a malicious logon script because of the ability to specify the configuration folder on the command line. If CRT or SecureCRT are launched from a URL, any /F option will be ignored. |
||||||||||||||||||||
Posted: November 23, 2004 Description When launching CRT and SecureCRT 4.0 and 4.1 from a URL, this vulnerability allowed the attacker to run a malicious logon script because of the ability to specify the configuration folder on the command line. Successful exploitation allows execution of arbitrary commands via a malicious logon script with the privileges of the user running CRT or SecureCRT. This vulnerability is only applicable to users who have made CRT or SecureCRT their default Telnet client. CRT 4.1.9 and SecureCRT 4.1.9 (or newer) provide a fix for this vulnerability. CRT and SecureCRT no longer allow the configuration folder (/F option) to be passed to the command line if the command line is part of a URL. Other command-line arguments are still supported and must come before the URL. Earlier versions of these client applications may be vulnerable as well. VanDyke encourages all users whose licenses were purchased prior to October 26, 2004 to consider upgrading to the current version(s) of their licensed applications.
|
VanDyke Software uses cookies to give you the best online experience. Before continuing to use this site, please confirm that you agree to our use of cookies. Please see our Cookie Usage for details.
Here you can control cookies using the checkboxes below. Some cookies are essential for the use of our website and cannot be disabled. Others provide a convenience to the user and, if disabled, may reduce the ease of use of our site. Finally, some cookies provide anonymous analytic tracking data that help us provide the user with a richer browsing experience. You can elect to disable these cookies as well.