HIGH
Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server before 4.4.5, and Manager 2.12 and earlier, when running on Windows, might allow local users to gain privileges via a malicious program file under "Program Files" or its subdirectories
Published Aug 23, 2006
7.2
HIGHCVSS 2.0
EPSS 0.34%
Description
Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server before 4.4.5, and Manager 2.12 and earlier, when running on Windows, might allow local users to gain privileges via a malicious program file under "Program Files" or its subdirectories.
Affected products
No data.
OR
- 4.0
- 4.0.1
- 4.0.3
- 4.0.4
- 4.0.5
- 4.2
- 4.2.1
- 4.3
- 4.3.1
- 4.3.1j
- 4.3.2
- 4.3.3
- 4.3.4
- 4.3.5
- 4.3.6
- 4.3.7
- 4.3.8k
- 4.4
- 4.4.1
- 4.4.2
- 4.4.3
- 4.4.4
- 4.4.5
- 5.0
- 5.0.1
- 5.0
- 5.0.1
- 1.3
- 1.4
- 2.1.2
- 4.0
- 4.0.3
- 4.0.4
- 4.0.5
- 4.2.1
- 4.3
- 4.3.1
- 4.3.2
- 4.3.3
- 4.3.4
- 4.3.5
- 4.3.6
- 4.3.7
- 4.4
- 4.4.2
- 4.4.3
- 4.4.4
- 4.4.5
- 5.0
- 5.0.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (4)
- http://securitytracker.com/id?1016743 vdb-entryx_refsource_SECTRACK
- http://www.securityfocus.com/bid/19679 vdb-entryx_refsource_BID
- http://www.ssh.com/company/news/2006/english/security/article/775/ x_refsource_CONFIRMPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28566 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://securitytracker.com/id?1016743 | vdb-entryx_refsource_SECTRACK | |
| http://www.securityfocus.com/bid/19679 | vdb-entryx_refsource_BID | |
| http://www.ssh.com/company/news/2006/english/security/article/775/ | x_refsource_CONFIRMPatchVendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/28566 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 23, 2006
Updated Aug 7, 2024
Reserved Aug 23, 2006
Link CVE-2006-4315
CISA Vulnrichment
Updated n/a