The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.
References
Link | Resource |
---|---|
http://matt.ucc.asn.au/dropbear/CHANGES | Vendor Advisory |
http://www.securityfocus.com/bid/10803 | Third Party Advisory VDB Entry |
http://www.osvdb.org/8137 | Broken Link |
http://secunia.com/advisories/12153 | Third Party Advisory |
http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml | Third Party Advisory |
http://secunia.com/advisories/28935 | Third Party Advisory |
http://www.vupen.com/english/advisories/2008/0543 | Third Party Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/40490 | Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16810 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2004-12-30 21:00
Updated : 2018-10-30 09:28
NVD link : CVE-2004-2486
Mitre link : CVE-2004-2486
JSON object : View
CWE
Products Affected
dropbear_ssh_project
- dropbear_ssh