First published: Wed Aug 23 2006(Updated: )
Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server before 4.4.5, and Manager 2.12 and earlier, when running on Windows, might allow local users to gain privileges via a malicious program file under "Program Files" or its subdirectories.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SSH Tectia Client | =4.0 | |
SSH Tectia Client | =4.0.1 | |
SSH Tectia Client | =4.0.3 | |
SSH Tectia Client | =4.0.4 | |
SSH Tectia Client | =4.0.5 | |
SSH Tectia Client | =4.2 | |
SSH Tectia Client | =4.2.1 | |
SSH Tectia Client | =4.3 | |
SSH Tectia Client | =4.3.1 | |
SSH Tectia Client | =4.3.1j | |
SSH Tectia Client | =4.3.2 | |
SSH Tectia Client | =4.3.3 | |
SSH Tectia Client | =4.3.4 | |
SSH Tectia Client | =4.3.5 | |
SSH Tectia Client | =4.3.6 | |
SSH Tectia Client | =4.3.7 | |
SSH Tectia Client | =4.3.8k | |
SSH Tectia Client | =4.4 | |
SSH Tectia Client | =4.4.1 | |
SSH Tectia Client | =4.4.2 | |
SSH Tectia Client | =4.4.3 | |
SSH Tectia Client | =4.4.4 | |
SSH Tectia Client | =4.4.5 | |
SSH Tectia Client | =5.0 | |
SSH Tectia Client | =5.0.1 | |
SSH Tectia Connector | =5.0 | |
SSH Tectia Connector | =5.0.1 | |
SSH Tectia Manager | =1.3 | |
SSH Tectia Manager | =1.4 | |
SSH Tectia Manager | =2.1.2 | |
SSH Tectia Server | =4.0 | |
SSH Tectia Server | =4.0.3 | |
SSH Tectia Server | =4.0.4 | |
SSH Tectia Server | =4.0.5 | |
SSH Tectia Server | =4.2.1 | |
SSH Tectia Server | =4.3 | |
SSH Tectia Server | =4.3.1 | |
SSH Tectia Server | =4.3.2 | |
SSH Tectia Server | =4.3.3 | |
SSH Tectia Server | =4.3.4 | |
SSH Tectia Server | =4.3.5 | |
SSH Tectia Server | =4.3.6 | |
SSH Tectia Server | =4.3.7 | |
SSH Tectia Server | =4.4 | |
SSH Tectia Server | =4.4.2 | |
SSH Tectia Server | =4.4.3 | |
SSH Tectia Server | =4.4.4 | |
SSH Tectia Server | =4.4.5 | |
SSH Tectia Server | =5.0 | |
SSH Tectia Server | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4315 has a severity level that can lead to local privilege escalation for users on affected systems.
To fix CVE-2006-4315, it is recommended to update to the latest versions of SSH Tectia products that address this vulnerability.
CVE-2006-4315 affects multiple SSH Tectia products, including Client/Server versions 5.0.0, 5.0.1, as well as earlier versions before 4.4.5.
Yes, local users can exploit CVE-2006-4315 by placing a malicious program file in the unquoted search path.
CVE-2006-4315 specifically impacts SSH Tectia products when they are running on Windows environments.