LWN.net Logo

dropbear: code execution

Package(s):dropbear CVE #(s):CVE-2012-0920
Created:April 25, 2012 Updated:August 13, 2012
Description: From the Debian advisory:

Danny Fullerton discovered a use-after-free in the Dropbear SSH daemon, resulting in potential execution of arbitrary code. Exploitation is limited to users, who have been authenticated through public key authentication and for which command restrictions are in place.

Alerts:
Debian DSA-2456-1 2012-04-24
Fedora FEDORA-2012-10934 2012-07-29
Mageia MGASA-2012-0205 2012-08-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds