Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Dropbear SSH Server < 0.47.0 svr_ses.childpidsize Remote Overflow

Medium

Synopsis

The remote host is vulnerable to a buffer overflow.

Description

The remote host is running a version of the Dropbear SSH server prior to 0.47.0 that is vulnerable to a remote buffer overflow. An attacker exploiting this flaw would need to be able to log into a valid account. After logging in, the user would send a malformed request to the SSH server which would result in a buffer overflow and execution of arbitrary code.

Solution

Upgrade to version 0.47.0 or higher.