Release date:
Updated on:
Affected Systems:
Dropbear SSH Server 2011.54
Dropbear SSH Server 0.52
Unaffected system:
Dropbear SSH Server 2012.55
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52159
CVE (CAN) ID: CVE-2012-0920
Dropbear SSH Server is a small Secure Shell Server suitable for Embedded environments.
The Dropbear SSH Server has a remote code execution vulnerability. Attackers can exploit this vulnerability to execute arbitrary code with root permissions. To exploit this vulnerability, you must pass authentication.
<* Source: Danny Fullerton
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Dropbear
--------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://matt.ucc.asn.au/dropbear/