|
|
Subscribe / Log in / New account

dropbear: code execution

Package(s):dropbear CVE #(s):CVE-2016-7409
Created:February 21, 2017 Updated:February 22, 2017
Description: From the Gentoo advisory:

Multiple vulnerabilities have been found in Dropbear, the worst of which allows remote attackers to execute arbitrary code.

A remote attacker could possibly execute arbitrary code with root privileges if usernames containing special characters can be created on a system. Also, a dbclient user who can control username or host arguments could potentially run arbitrary code with the privileges of the process.

In addition, a remote attacker could entice a user to process a specially crafted SSH key using dropbearconvert, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition.

Alerts:
Gentoo 201702-23 dropbear 2017-02-21

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds