vendor:
ZOC SSH Client
by:
Dolev Farhi
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: ZOC SSH Client
Affected Version From: 07.03.2000
Affected Version To: 07.03.2000
Patch Exists: Yes
Related CWE: N/A
CPE: a:emtec:zoc_ssh_client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2015
ZOC SSH Client v.7.03.0 Buffer overflow vulnerability (SEH)
A buffer overflow vulnerability exists in ZOC SSH Client v.7.03.0. An attacker can create a new connection, run a python script to generate a string of 'AAAA...' and copy it to the clipboard. The attacker can then paste the string in the server address and attempt to connect, which can lead to a buffer overflow.
Mitigation:
Upgrade to the latest version of ZOC SSH Client.