PT-2016-3220 · Dropbear+1 · Dropbear Ssh+1

Andrej Nemec

·

Published

2016-07-12

·

Updated

2017-03-04

·

CVE-2016-7407

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dropbear SSH versions prior to 2016.74
Description The issue allows attackers to execute arbitrary code via a crafted OpenSSH key file. This is due to insufficient input validation in the Dropbear SSH package. The dropbearconvert command is specifically vulnerable to this issue, allowing a remote attacker to execute arbitrary code using a specially prepared OpenSSH key file.
Recommendations For versions prior to 2016.74, update to version 2016.74 or later to resolve the issue. As a temporary workaround, consider restricting the use of the dropbearconvert command until a patch is applied. Avoid using the dropbearconvert command with untrusted OpenSSH key files until the issue is resolved.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1786
BDU:2017-02586
CVE-2016-7407
DLA-634-1
MGASA-2016-0301

Affected Products

Alt Linux
Dropbear Ssh