CVE-2012-0920
Last modified
CVE-2012-0920 is a vulnerability of currently unknown severity. Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote authenticated users to execute arbitrary code and bypass command restrictions via multiple crafted command requests, related to "channels concurrency.". EPSS estimates a 6.49% chance of exploitation in the next 30 days.
Description
Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote authenticated users to execute arbitrary code and bypass command restrictions via multiple crafted command requests, related to "channels concurrency."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dropbear Ssh Project | Dropbear Ssh | >= 0.52, <= 2012.54 |
| Debian | Debian Linux | 6.0 |
| Debian | Debian Linux | 7.0 |
References
- http://matt.ucc.asn.au/dropbear/CHANGESVendor Advisory
- http://secunia.com/advisories/48147Third Party Advisory
- http://secunia.com/advisories/48929Third Party Advisory
- http://www.debian.org/security/2012/dsa-2456Third Party Advisory
- http://www.osvdb.org/79590Broken Link
- http://www.securityfocus.com/bid/52159Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73444Third Party Advisory, VDB Entry
- https://secure.ucc.asn.au/hg/dropbear/rev/818108bf7749Vendor Advisory
- https://www.mantor.org/~northox/misc/CVE-2012-0920.htmlThird Party Advisory
- http://matt.ucc.asn.au/dropbear/CHANGESVendor Advisory
- http://secunia.com/advisories/48147Third Party Advisory
- http://secunia.com/advisories/48929Third Party Advisory
- http://www.debian.org/security/2012/dsa-2456Third Party Advisory
- http://www.osvdb.org/79590Broken Link
- http://www.securityfocus.com/bid/52159Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73444Third Party Advisory, VDB Entry
- https://secure.ucc.asn.au/hg/dropbear/rev/818108bf7749Vendor Advisory
- https://www.mantor.org/~northox/misc/CVE-2012-0920.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-0920?
How severe is CVE-2012-0920?
How do I fix CVE-2012-0920?
Are you affected by CVE-2012-0920?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
