|
A remote overflow exists in SSH2. The SSH2 software fails to handle strings with null characters in the length field, resulting in a buffer overflow. By sending a specially-crafted packet with a string field containing null characters during SSH key exchange and initialization, a remote attacker could overflow a buffer and crash or execute arbitrary code on the system with privileges of the SSH process, resulting in a loss of confidentiality, integrity or availability.
|