CVE-2006-2407: Buffer Overflow
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange algorithm string.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2407?
CVE-2006-2407 is considered critical due to its potential for remote code execution.
How do I fix CVE-2006-2407?
To mitigate CVE-2006-2407, users should update to the latest versions of the affected software or apply any security patches provided by the vendor.
Which software is affected by CVE-2006-2407?
CVE-2006-2407 affects WeOnlyDo wodSSHServer versions 1.2.7 and 1.3.3 DEMO, FreeSSHd version 1.0.9, and freeFTPd version 1.0.10.
Can CVE-2006-2407 be exploited remotely?
Yes, CVE-2006-2407 can be exploited remotely by attackers through a specially crafted key exchange algorithm string.
What type of attack is associated with CVE-2006-2407?
CVE-2006-2407 is associated with a stack-based buffer overflow attack that can lead to arbitrary code execution.