Vulnerability Description
Buffer overflow in SecureCRT 5.0.4 and earlier and SecureFX 3.0.4 and earlier allows remote attackers to have an unknown impact when a Unicode string is converted to a "narrow" string.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Van Dyke Technologies | Securecrt | 5.0 |
| Van Dyke Technologies | Securefx | 3.0 |
References
- http://secunia.com/advisories/19040PatchVendor Advisory
- http://www.securityfocus.com/bid/16935
- http://www.vandyke.com/products/securecrt/history.txt
- http://www.vandyke.com/products/securefx/history.txt
- http://www.vupen.com/english/advisories/2006/0806
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25092
- http://secunia.com/advisories/19040PatchVendor Advisory
- http://www.securityfocus.com/bid/16935
- http://www.vandyke.com/products/securecrt/history.txt
- http://www.vandyke.com/products/securefx/history.txt
- http://www.vupen.com/english/advisories/2006/0806
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25092
FAQ
What is CVE-2006-1038?
CVE-2006-1038 is a vulnerability with a CVSS score of 10.0 (HIGH). Buffer overflow in SecureCRT 5.0.4 and earlier and SecureFX 3.0.4 and earlier allows remote attackers to have an unknown impact when a Unicode string is converted to a "narrow" string.
How severe is CVE-2006-1038?
CVE-2006-1038 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1038?
Check the references section above for vendor advisories and patch information. Affected products include: Van Dyke Technologies Securecrt, Van Dyke Technologies Securefx.