Nessus Plugin #11339

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

scp File Create/Overwrite

Family:
Gain a shell remotely
Category:
infos
Copyright:
This script is Copyright (C) 2003 Xue Yong Zhi
Summary:
Checks for the remote SSH version
Version:
$Revision: 1.4 $
Cve_id:
CVE-2000-0992
Bugtraq_id:
1742
Xrefs:
-
Description:

You are running OpenSSH 1.2.3, or 1.2.

This version has directory traversal vulnerability in scp, it allows
a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.

Solution :
Patch and New version are available from SSH/OpenSSH.

Risk factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.