First published: Fri Sep 02 2005(Updated: )
WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) processes access and deny lists in a case-sensitive manner, when previous versions were case-insensitive, which might allow remote attackers to bypass intended restrictions and login to accounts that should be denied.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F-Secure SSH Server | =5.1 | |
F-Secure SSH Server | =5.2 | |
F-Secure SSH Server | =5.3 | |
Attachmate Reflection for Secure IT | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2771 is classified as a medium severity vulnerability.
To fix CVE-2005-2771, upgrade to a version of F-Secure SSH Server or WRQ Reflection for Secure IT Windows Server that handles access lists case-sensitively.
CVE-2005-2771 affects users of F-Secure SSH Server versions 5.1, 5.2, 5.3 and WRQ Reflection for Secure IT Windows Server version 6.0.
CVE-2005-2771 is caused by the case-sensitive handling of access and deny lists in newer software versions.
The potential impact of CVE-2005-2771 includes unauthorized access to accounts that should be restricted.