Dropbear SSH Server Remote Buffer Overflow Vulnerability
BID:15923
CVE-2005-4178 |Info
Dropbear SSH Server Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 15923 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-4178 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2005 12:00AM |
| Updated: | May 09 2006 07:54PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Gentoo Linux Dropbear SSH Server 0.47 Dropbear SSH Server 0.46 Dropbear SSH Server 0.45 Dropbear SSH Server 0.44 Dropbear SSH Server 0.43 Dropbear SSH Server 0.42 Dropbear SSH Server 0.41 Dropbear SSH Server 0.40 |
| Not Vulnerable: |
Dropbear SSH Server 0.47 |
Discussion
Dropbear SSH Server Remote Buffer Overflow Vulnerability
Dropbear SSH Server is prone to a remote buffer-overflow vulnerability.
Specifically, the vulnerability presents itself when the application handles excessive string data supplied by an authenticated user.
A successful attack may facilitate arbitrary code execution. Exploitation of this vulnerability may allow an attacker to gain superuser access to the computer.
Dropbear SSH Server versions prior to 0.47 are affected.
Dropbear SSH Server is prone to a remote buffer-overflow vulnerability.
Specifically, the vulnerability presents itself when the application handles excessive string data supplied by an authenticated user.
A successful attack may facilitate arbitrary code execution. Exploitation of this vulnerability may allow an attacker to gain superuser access to the computer.
Dropbear SSH Server versions prior to 0.47 are affected.
Exploit / POC
Dropbear SSH Server Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Dropbear SSH Server Remote Buffer Overflow Vulnerability
Solution:
The vendor has released Dropbear 0.47 to address this issue. Please see the referenced advisories for more information.
Dropbear SSH Server 0.40
Dropbear SSH Server 0.41
Dropbear SSH Server 0.42
Dropbear SSH Server 0.43
Dropbear SSH Server 0.44
Dropbear SSH Server 0.45
Dropbear SSH Server 0.46
Solution:
The vendor has released Dropbear 0.47 to address this issue. Please see the referenced advisories for more information.
Dropbear SSH Server 0.40
-
Dropbear dropbear-0.47.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.47.tar.gz
Dropbear SSH Server 0.41
-
Dropbear dropbear-0.47.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.47.tar.gz
Dropbear SSH Server 0.42
-
Dropbear dropbear-0.47.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.47.tar.gz
Dropbear SSH Server 0.43
-
Dropbear dropbear-0.47.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.47.tar.gz
Dropbear SSH Server 0.44
-
Dropbear dropbear-0.47.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.47.tar.gz
Dropbear SSH Server 0.45
-
Debian dropbear_0.45-2sarge0_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45- 2sarge0_alpha.deb -
Debian dropbear_0.45-2sarge0_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45- 2sarge0_amd64.deb -
Debian dropbear_0.45-2sarge0_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45- 2sarge0_arm.deb -
Debian dropbear_0.45-2sarge0_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45- 2sarge0_hppa.deb -
Debian dropbear_0.45-2sarge0_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45- 2sarge0_i386.deb -
Debian dropbear_0.45-2sarge0_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45- 2sarge0_ia64.deb -
Debian dropbear_0.45-2sarge0_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45- 2sarge0_m68k.deb -
Debian dropbear_0.45-2sarge0_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45- 2sarge0_mips.deb -
Debian dropbear_0.45-2sarge0_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45- 2sarge0_mipsel.deb -
Debian dropbear_0.45-2sarge0_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45- 2sarge0_powerpc.deb -
Debian dropbear_0.45-2sarge0_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45- 2sarge0_s390.deb -
Debian dropbear_0.45-2sarge0_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45- 2sarge0_sparc.deb -
Dropbear dropbear-0.47.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.47.tar.gz
Dropbear SSH Server 0.46
-
Dropbear dropbear-0.47.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.47.tar.gz
References
Dropbear SSH Server Remote Buffer Overflow Vulnerability
References:
References:
- Dropbear 0.47 (and security fix) (Matt Johnston)
- Dropbear SSH Server Homepage (Dropbear)