CVE-2012-0920
dropbear - use after free
EPSS 6.5%
描述
Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote authenticated users to execute arbitrary code and bypass command restrictions via multiple crafted command requests, related to "channels concurrency."
如何修補 CVE-2012-0920
要修補 CVE-2012-0920,請將受影響套件升級到下列已修補版本。
- Debian/dropbear—升級至 2012.55-1 或更新版本
- Debian/dropbear—升級至 0.52-5+squeeze1 或更新版本
CVE-2012-0920 正在被利用嗎?
中等 — EPSS 為 6.5%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 2012.55-1
- from 0, < 0.52-5+squeeze1