CVE-2012-6066: Critical severity freesshd vulnerability
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6066?
CVE-2012-6066 is classified as a critical vulnerability due to its potential for authentication bypass.
What software versions are affected by CVE-2012-6066?
CVE-2012-6066 affects freeSSHd versions up to and including 1.2.6, as well as specific earlier versions such as 1.2.1 and 1.2.2.
How do I fix CVE-2012-6066?
To mitigate CVE-2012-6066, users should upgrade freeSSHd to a version beyond 1.2.6 that addresses this vulnerability.
What are the risks of CVE-2012-6066?
The risks associated with CVE-2012-6066 include unauthorized access and potential control over compromised systems.
Is there a workaround for CVE-2012-6066 before I can update?
While there is no official workaround for CVE-2012-6066, disabling services relying on affected software can reduce immediate risk.