Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian Wheezy DLA-948-1: Critical Dropbear SSH2 Information Leak

debian lts
Calendar Grey May 21, 2017
Dist Debian Esm H88
A recent patch for Dropbear fixes a significant data exposure flaw in Debian LTS impacting SSH2. Please update promptly.
A vulnerability was found in Dropbear, a lightweight SSH2 server and client

Summary

CVE-2017-9079

Jann Horn discovered a local information leak in parsing the
.authorized_keys file.


For Debian 7 "Wheezy", this problem has been fixed in version
2012.55-1.3+deb7u2.

We recommend that you upgrade your dropbear packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: dropbear
Version: 2012.55-1.3+deb7u2
CVE ID: CVE-2017-9079

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here