Dropbear Hostkey Mismatch Warning Weakness
BID:22761
Info
Dropbear Hostkey Mismatch Warning Weakness
| Bugtraq ID: | 22761 |
| Class: | Design Error |
| CVE: |
CVE-2007-1099 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2007 12:00AM |
| Updated: | May 12 2015 07:34PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Dropbear SSH Server 0.47 Dropbear SSH Server 0.46 Dropbear SSH Server 0.45 Dropbear SSH Server 0.44 Dropbear SSH Server 0.43 Dropbear SSH Server 0.42 Dropbear SSH Server 0.41 Dropbear SSH Server 0.40 Dropbear SSH Server 0.39 Dropbear SSH Server 0.38 Dropbear SSH Server 0.37 Dropbear SSH Server 0.36 Dropbear SSH Server 0.35 Dropbear SSH Server 0.34 Dropbear SSH Server 0.33 Dropbear SSH Server 0.32 Dropbear SSH Server 0.31 Dropbear SSH Server 0.30 Dropbear SSH Server 0.29 Dropbear SSH Server 0.28 Dropbear SSH Server 0.48 |
| Not Vulnerable: |
Dropbear SSH Server 0.49 |
Discussion
Dropbear Hostkey Mismatch Warning Weakness
Dropbear is prone to a security weakness -- it fails to properly warn users of a hostkey mismatch.
Dropbear versions prior to 0.49 are vulnerable to this issue.
Dropbear is prone to a security weakness -- it fails to properly warn users of a hostkey mismatch.
Dropbear versions prior to 0.49 are vulnerable to this issue.
Exploit / POC
Dropbear Hostkey Mismatch Warning Weakness
An exploit is not required.
An exploit is not required.
Solution / Fix
Dropbear Hostkey Mismatch Warning Weakness
Solution:
The vendor has released updates to address this issue.
Solution:
The vendor has released updates to address this issue.
References
Dropbear Hostkey Mismatch Warning Weakness
References:
References:
- Dropbear Changelog (Dropbear)
- Dropbear SSH Server Homepage (Dropbear)