CVE-2017-1000475: High severity freesshd vulnerability
Published Jan 24, 2018
·Updated
FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated privileges.
Affected Software
1 affected component
FreeSSHd freeSSHd=1.3.1
Event History
Jan 24, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000475?
CVE-2017-1000475 is considered a high-severity vulnerability due to its potential for local users to gain elevated privileges.
2
How do I fix CVE-2017-1000475?
To fix CVE-2017-1000475, update FreeSSHd to a version that properly quotes the service paths or apply a workaround to quote the paths manually.
3
Who is affected by CVE-2017-1000475?
CVE-2017-1000475 affects all local users on systems running FreeSSHd version 1.3.1.
4
What is the nature of the vulnerability described in CVE-2017-1000475?
CVE-2017-1000475 involves an unquoted path service vulnerability that allows local users to execute arbitrary code with elevated privileges.
5
Can CVE-2017-1000475 be exploited remotely?
CVE-2017-1000475 cannot be exploited remotely; it requires local access to the affected system.