SSH Tectia pathname parsing privilege escalation
| ssh-tectia-pathname-privilege-escalation (28566) |
Description:
SSH Tectia Client, Server, Connector, and Manager running on Microsoft Windows could allow a local attacker to gain elevated privileges, caused by a vulnerability regarding an unquoted Windows search path. A local attacker with permissions to create a file in the system root or the "Program Files" directory could exploit this vulnerability by creating a malicious executable that would be executed with SYSTEM privileges once the affected SSH Tectia process starts.
Platforms Affected:
- SSH, Tectia Client 4.0
- SSH, Tectia Client 4.0.1
- SSH, Tectia Client 4.0.3
- SSH, Tectia Client 4.0.4
- SSH, Tectia Client 4.0.5
- SSH, Tectia Client 4.2
- SSH, Tectia Client 4.2.1
- SSH, Tectia Client 4.3
- SSH, Tectia Client 4.3.1
- SSH, Tectia Client 4.3.1J
- SSH, Tectia Client 4.3.2
- SSH, Tectia Client 4.3.3
- SSH, Tectia Client 4.3.4
- SSH, Tectia Client 4.3.5
- SSH, Tectia Client 4.3.6
- SSH, Tectia Client 4.3.7
- SSH, Tectia Client 4.3.8K
- SSH, Tectia Client 4.4
- SSH, Tectia Client 4.4.1
- SSH, Tectia Client 4.4.2
- SSH, Tectia Client 4.4.3
- SSH, Tectia Client 4.4.4
- SSH, Tectia Client 4.4.5
- SSH, Tectia Client 5.0
- SSH, Tectia Client 5.0.1
- SSH, Tectia Connector 5.0
- SSH, Tectia Connector 5.0.1
- SSH, Tectia Manager 1.3
- SSH, Tectia Manager 1.4
- SSH, Tectia Manager 2.1.2
- SSH, Tectia Server 4.0
- SSH, Tectia Server 4.0.3
- SSH, Tectia Server 4.0.4
- SSH, Tectia Server 4.0.5
- SSH, Tectia Server 4.2.1
- SSH, Tectia Server 4.3
- SSH, Tectia Server 4.3.1
- SSH, Tectia Server 4.3.2
- SSH, Tectia Server 4.3.3
- SSH, Tectia Server 4.3.4
- SSH, Tectia Server 4.3.5
- SSH, Tectia Server 4.3.6
- SSH, Tectia Server 4.3.7
- SSH, Tectia Server 4.4
- SSH, Tectia Server 4.4.2
- SSH, Tectia Server 4.4.3
- SSH, Tectia Server 4.4.4
- SSH, Tectia Server 4.4.5
- SSH, Tectia Server 5.0
- SSH, Tectia Server 5.0.1
Remedy:
Refer to SSH Company News August 23, 2006 for patch or upgrade information See References.
Consequences:
Gain Privileges
References:
- SSH Communications Security Web site, SSH - Products - SSH Tectia Manager at http://www.ssh.com/products/manager/.
- SSH Company News August 23, 2006 , SSH Tectia Windows Pathname Parsing Vulnerability at http://www.ssh.com/company/news/article/775/.
- BID-19679: SSH Tectia Windows Path Specification Privilege Escalation Vulnerability
- CVE-2006-4315: Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server before 4.4.5, and Manager 2.12 and earlier, when running on Windows, might allow local users to gain privileges via a malicious program file under Program Files or its subdirectories.
- SECTRACK ID: 1016743: SSH Tectia Client/Server/Connector/Manager Pathname Parsing Flaw Lets Local Users Gain Elevated Privileges
Reported:
Aug 23, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
