CVE-2006-2421: Buffer Overflow
Published May 17, 2006
·Updated
Stack-based buffer overflow in Pragma FortressSSH 4.0.7.20 allows remote attackers to execute arbitrary code via long SSHMSGKEXINIT messages, which may cause an overflow when being logged. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
1 affected component
Pragma Systems Fortressssh<=4.0.7.20
Event History
May 17, 2006
CVE Published
10:06 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2421?
CVE-2006-2421 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2006-2421?
To mitigate CVE-2006-2421, it is recommended to upgrade FortressSSH to a version higher than 4.0.7.20.
3
Which versions are affected by CVE-2006-2421?
CVE-2006-2421 affects Pragma Systems FortressSSH version 4.0.7.20 and all prior versions.
4
What type of vulnerability is CVE-2006-2421?
CVE-2006-2421 is a stack-based buffer overflow vulnerability.
5
Can CVE-2006-2421 be exploited remotely?
Yes, CVE-2006-2421 can be exploited remotely via crafted SSH_MSG_KEXINIT messages.