RSS   Vulnerabilities for 'Tectia manager'   RSS

2006-10-24
 
CVE-2006-5484

CWE-Other
 

 
SSH Tectia Client/Server/Connector 5.1.0 and earlier, Manager 2.2.0 and earlier, and other products, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents Tectia from correctly verifying X.509 and other certificates that use PKCS #1, a similar issue to CVE-2006-4339.

 
2006-08-23
 
CVE-2006-4316

 

 
SSH Tectia Management Agent 2.1.2 allows local users to gain root privileges by running a program called sshd, which is obtained from a process listing when the "Restart" action is selected from the Management server GUI, which causes the agent to locate the pathname of the user's program and restart it with root privileges.

 
 
CVE-2006-4315

 

 
Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server before 4.4.5, and Manager 2.12 and earlier, when running on Windows, might allow local users to gain privileges via a malicious program file under "Program Files" or its subdirectories.

 

 >>> Vendor: SSH 10 Products
SSH
SSH2
Secure shell
Secure shell for servers
Tectia server
Tectia client
Tectia connector
Tectia manager
Tectia client server connector
Tectia connectsecure


Copyright 2024, cxsecurity.com

 

Back to Top