CVE-2012-6067: Critical severity freesshd freeftpd vulnerability
Published Dec 4, 2012
·Updated
freeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.
Affected Software
11 affected components
freeFTPd freeFTPd<=1.0.11
freeFTPd freeFTPd=1.0
freeFTPd freeFTPd=1.0.1
freeFTPd freeFTPd=1.0.2
freeFTPd freeFTPd=1.0.3
freeFTPd freeFTPd=1.0.4
freeFTPd freeFTPd=1.0.5
freeFTPd freeFTPd=1.0.6
freeFTPd freeFTPd=1.0.7
freeFTPd freeFTPd=1.0.8
freeFTPd freeFTPd=1.0.10
Event History
Dec 4, 2012
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6067?
CVE-2012-6067 is classified as a medium severity vulnerability that allows remote authentication bypass.
2
How do I fix CVE-2012-6067?
To mitigate CVE-2012-6067, upgrade freeFTPd to version 1.0.12 or later.
3
What types of software are affected by CVE-2012-6067?
CVE-2012-6067 affects freeFTPd versions up to and including 1.0.11.
4
Can exploitation of CVE-2012-6067 be easily detected?
Exploitation of CVE-2012-6067 can be challenging to detect as it occurs during SFTP sessions.
5
What actions can attackers take by exploiting CVE-2012-6067?
Attackers exploiting CVE-2012-6067 can gain unauthorized access to the server by bypassing authentication.