PT-2007-2527 · Dropbear · Dropbear Ssh Client
Publicado
2007-02-26
·
Atualizado
2018-10-30
·
CVE-2007-1099
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Dropbear SSH client versions prior to 0.49
Description
The issue concerns a hostkey mismatch detection problem. When a hostkey mismatch is detected, the software does not provide sufficient warnings to the user. This could potentially allow remote attackers to conduct man-in-the-middle attacks.
Recommendations
For versions prior to 0.49, update to version 0.49 or later to resolve the issue. As a temporary workaround, consider increasing user awareness about hostkey mismatches to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dropbear Ssh Client