PT-2017-3173 · Dropbear+1 · Dropbear Ssh+1

Andrej Nemec

·

Published

2016-07-26

·

Updated

2025-11-04

·

CVE-2016-7406

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dropbear SSH versions prior to 2016.74
Description The issue is related to a format string vulnerability that allows remote attackers to execute arbitrary code. This is achieved by using format string specifiers in the username or host argument. The vulnerability exists due to insufficient input validation.
Recommendations For versions prior to 2016.74, update to version 2016.74 or later to resolve the issue. As a temporary workaround, consider restricting the use of format string specifiers in the username and host arguments until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1786
BDU:2017-02587
CVE-2016-7406
DLA-634-1
MGASA-2016-0301

Affected Products

Alt Linux
Dropbear Ssh