漏洞信息详情
Matt Johnston Dropbear SSH 远程拒绝服务漏洞
- CNNVD编号:CNNVD-200603-228
- 危害等级: 中危
- CVE编号:
CVE-2006-1206
- 漏洞类型:
其他
- 发布时间:
2006-03-13
- 威胁类型:
远程
- 更新时间:
2006-03-15
- 厂 商:
matt_johnston - 漏洞来源:
Discovery of this … -
漏洞简介
Matt Johnston Dropbear SSH 服务器0.47及其早期版本,当使用在嵌入式Linux设备和一般目的操作系统上时,可以让远程攻击者通过以下途径制造一个拒绝服务(连接槽用完): 超过MAX_UNAUTH_CLIENTS中定义值30的大量连接尝试。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Dropbear SSH Server 0.28
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.29
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.30
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.31
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.32
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.33
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.34
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.35
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.36
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.37
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.38
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.39
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.40
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.41
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.42
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.43
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.44
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.45
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.46
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.47
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
参考网址
来源: BID
名称: 17024
链接:http://www.securityfocus.com/bid/17024
来源: XF
名称: dropbear-connection-dos(25075)
链接:http://xforce.iss.net/xforce/xfdb/25075
来源: BUGTRAQ
名称: 20060307 Dropbear SSH server Denial of Service
链接:http://www.securityfocus.com/archive/1/archive/1/426999/100/0/threaded
来源: SECTRACK
名称: 1015742