PT-2021-11987 · Dropbear+1 · Dropbear+1

Published

2020-05-25

·

Updated

2024-05-03

·

CVE-2020-36254

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Dropbear versions prior to 2020.79
Description: The issue is related to the handling of filenames in scp.c, specifically with . or an empty filename. This is a related issue to a previously known problem.
Recommendations: For versions prior to 2020.79, update to version 2020.79 or later to resolve the issue.

Fix

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2113
ALT-PU-2024-4252
ALT-PU-2024-7377
BDU:2025-13198
CVE-2020-36254

Affected Products

Alt Linux
Dropbear