Dropbear SSH服务器数字签名标准未明的认证漏洞

漏洞信息详情

Dropbear SSH服务器数字签名标准未明的认证漏洞

漏洞简介

Dropbear SSH Server 0.43以前版本的DSS的验证码释放未初始化的变量,远程攻击者利用该漏洞获取访问权限。

漏洞公告

The vendor has released an upgrade dealing with this issue.
Dropbear SSH Server 0.28

Dropbear SSH Server 0.29

Dropbear SSH Server 0.30

Dropbear SSH Server 0.31

Dropbear SSH Server 0.32

Dropbear SSH Server 0.33

Dropbear SSH Server 0.34

Dropbear SSH Server 0.35

Dropbear SSH Server 0.36

Dropbear SSH Server 0.37

Dropbear SSH Server 0.38

Dropbear SSH Server 0.39

Dropbear SSH Server 0.40

Dropbear SSH Server 0.41

Dropbear SSH Server 0.42

参考网址

来源: XF
名称: dropbear-dss-code-execution(16810)
链接:http://xforce.iss.net/xforce/xfdb/16810

来源: BID
名称: 10803
链接:http://www.securityfocus.com/bid/10803

来源: OSVDB
名称: 8137
链接:http://www.osvdb.org/8137

来源: SECUNIA
名称: 12153
链接:http://secunia.com/advisories/12153

来源: matt.ucc.asn.au
链接:http://matt.ucc.asn.au/dropbear/CHANGES

来源: XF
名称: cisco-unifiedipphone-ssh-bo(40490)
链接:http://xforce.iss.net/xforce/xfdb/40490

来源: VUPEN
名称: ADV-2008-0543
链接:http://www.frsirt.com/english/advisories/2008/0543

来源: CISCO
名称: 20080213 Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities
链接:http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml

来源: SECUNIA
名称: 28935
链接:http://secunia.com/advisories/28935

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享