SSH RSAREF Library Multiple Functions Local Overflow

This script is Copyright (C) 1999-2014 Tenable Network Security, Inc.

Synopsis :

The remote SSH server may allow execution of arbitrary code.

Description :

The remote SSH server is version 1.2.27 or earlier.

If this version was compiled against the RSAREF library, then it is
likely to be vulnerable to a buffer overflow that a remote attacker
could exploit to gain root privileges on the affected system.

To determine if you compiled ssh against the RSAREF library, type 'ssh
-V' on the remote host.

See also :

Solution :

Either re-compile ssh to avoid using the RSAREF library or upgrade to
SSH 2.x or later.

Risk factor :

High / CVSS Base Score : 9.3
CVSS Temporal Score : 8.8
Public Exploit Available : true

Family: Misc.

Nessus Plugin ID: 10269 ()

Bugtraq ID: 843

CVE ID: CVE-1999-0834