CVE-2008-2573: Buffer Overflow
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a long directory name in an SSHFXPOPENDIR (aka opendir) command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2573?
CVE-2008-2573 has a high severity rating due to its potential to allow remote authenticated users to execute arbitrary code.
How do I fix CVE-2008-2573?
To fix CVE-2008-2573, upgrade freeSSHd to a later version that resolves the buffer overflow vulnerability.
Who is affected by CVE-2008-2573?
Users of freeSSHd version 1.2.1 are affected by CVE-2008-2573 due to the vulnerable SFTP implementation.
What type of attack does CVE-2008-2573 enable?
CVE-2008-2573 enables remote authenticated users to exploit a stack-based buffer overflow to execute arbitrary code.
Is there any workaround for CVE-2008-2573?
Disabling SFTP file access or restricting access to trusted users may serve as a temporary workaround for CVE-2008-2573.