Security Advisory — SecureCRT® 2.x, 3.x, 4.0.x |
|||||||||||||||
SecureCRT is reported prone to a remote denial of service vulnerability. It is reported that supplying an excessive string value to the application through the hostname field may trigger this vulnerability. Apparently, this causes the client application to crash.SecureCRT 4.0.9 and earlier may be vulnerable when SSH2 is used. SecureCRT 4.1 or newer provides a fix for SSH2 connections. |
|||||||||||||||
Posted: January 14, 2005 Description The remote denial of service vulnerability described in this advisory is a denial of service on the local machine caused by SecureCRT crashing if an attempt is made to connect to an SSH2 session with an excessively long hostname. The remote machine is not affected by this vulnerability.
|
VanDyke Software uses cookies to give you the best online experience. Before continuing to use this site, please confirm that you agree to our use of cookies. Please see our Cookie Usage for details.
Here you can control cookies using the checkboxes below. Some cookies are essential for the use of our website and cannot be disabled. Others provide a convenience to the user and, if disabled, may reduce the ease of use of our site. Finally, some cookies provide anonymous analytic tracking data that help us provide the user with a richer browsing experience. You can elect to disable these cookies as well.