DoS in Bitvise WinSSH for Windows 2000

Ken Pfeil

March 19, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported March 16, 2002, by Peter Gründl.

VERSION AFFECTED

  • Bitvise WinSSH for Windows 2000

DESCRIPTION
When a user logs on to his or her account through the IMail Server Web interface, the application uses a unique URL to maintain the session authentication. A vulnerability exists in Bitvise’s WinSSH that can result in a Denial of Service (DoS) condition. Because of differences in the Secure Shell (SSH) daemon and the underlying socket layer, an attacker can abruptly end sessions without SSH properly freeing those sessions. Each incomplete connection would use a few memory handles and allocate nonpaged kernel memory.


VENDOR RESPONSE

The vendor, Bitvise, has released a new build that this condition doesn't affect. The company recommends that affected users download this updated version from http://www.bitvise.com/existing-users.html.


CREDIT
Discovered by Peter Gründl.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like