[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3859-1 dropbear -- dropbear

ID: oval:org.secpod.oval:def:602894Date: (C)2017-05-22   (M)2023-12-20
Class: PATCHFamily: unix




Two vulnerabilities were found in Dropbear, a lightweight SSH2 server and client: CVE-2017-9078 Mark Shepard discovered a double free in the TCP listener cleanup which could result in denial of service by an authenticated user if Dropbear is running with the "-a" option. CVE-2017-9079 Jann Horn discovered a local information leak in parsing the .authorized_keys file.

Platform:
Debian 8.x
Product:
dropbear
Reference:
DSA-3859-1
CVE-2017-9078
CVE-2017-9079
CVE    2
CVE-2017-9078
CVE-2017-9079
CPE    2
cpe:/a:matt_johnston:dropbear
cpe:/o:debian:debian_linux:8.x

© SecPod Technologies