PT-2016-3220 · Dropbear+1 · Dropbear Ssh+1
Andrej Nemec
·
Published
2016-07-12
·
Updated
2017-03-04
·
CVE-2016-7407
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Dropbear SSH versions prior to 2016.74
Description
The issue allows attackers to execute arbitrary code via a crafted OpenSSH key file. This is due to insufficient input validation in the Dropbear SSH package. The
dropbearconvert command is specifically vulnerable to this issue, allowing a remote attacker to execute arbitrary code using a specially prepared OpenSSH key file.Recommendations
For versions prior to 2016.74, update to version 2016.74 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
dropbearconvert command until a patch is applied. Avoid using the dropbearconvert command with untrusted OpenSSH key files until the issue is resolved.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Dropbear Ssh