CVE-2012-0920
Summary
| CVE | CVE-2012-0920 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-06-05 22:55:09 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote authenticated users to execute arbitrary code and bypass command restrictions via multiple crafted command requests, related to "channels concurrency." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:H/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 6.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Application | Dropbear Ssh Project | Dropbear Ssh | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-2456-1 dropbear | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| matt.ucc.asn.au/dropbear/CHANGES | af854a3a-2127-422b-91ae-364da2661108 | matt.ucc.asn.au | Vendor Advisory |
| dropbear: 818108bf7749 | af854a3a-2127-422b-91ae-364da2661108 | secure.ucc.asn.au | Vendor Advisory |
| CVE-2012-0920 - Dropbear SSH server use-after-free vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.mantor.org | Third Party Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| www.osvdb.org/79590 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| Dropbear SSH Server Use After Free Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.