The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.
References
Configurations
History
20 Nov 2024, 23:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://matt.ucc.asn.au/dropbear/CHANGES - Vendor Advisory | |
References | () http://secunia.com/advisories/12153 - Third Party Advisory | |
References | () http://secunia.com/advisories/28935 - Third Party Advisory | |
References | () http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml - Third Party Advisory | |
References | () http://www.osvdb.org/8137 - Broken Link | |
References | () http://www.securityfocus.com/bid/10803 - Third Party Advisory, VDB Entry | |
References | () http://www.vupen.com/english/advisories/2008/0543 - Third Party Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/16810 - Third Party Advisory, VDB Entry | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/40490 - Third Party Advisory, VDB Entry |
Information
Published : 2004-12-31 05:00
Updated : 2024-11-20 23:53
NVD link : CVE-2004-2486
Mitre link : CVE-2004-2486
CVE.ORG link : CVE-2004-2486
JSON object : View
Products Affected
dropbear_ssh_project
- dropbear_ssh
CWE