PT-2017-3173 · Dropbear+1 · Dropbear Ssh+1

Andrej Nemec

·

Publicado

2016-07-26

·

Atualizado

2025-11-04

·

CVE-2016-7406

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dropbear SSH versions prior to 2016.74
Description The issue is related to a format string vulnerability that allows remote attackers to execute arbitrary code. This is achieved by using format string specifiers in the username or host argument. The vulnerability exists due to insufficient input validation.
Recommendations For versions prior to 2016.74, update to version 2016.74 or later to resolve the issue. As a temporary workaround, consider restricting the use of format string specifiers in the username and host arguments until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1786
BDU:2017-02587
CVE-2016-7406
DLA-634-1
MGASA-2016-0301

Produtos afetados

Alt Linux
Dropbear Ssh