int(2058)

Vulnerability Bulletins


Desbordamiento de búfer en dropbear

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto con cuenta

System information

Property Value
Affected manufacturer GNU/Linux
Affected software dropbear

Description

Se ha descubierto una vulnerabilidad de desbordamiento de búfer en dropbear, un servidor y cliente SSH2.

La explotación de esta vulnerabilidad podría permitir a un usuario autenticado ejecutar código arbitrario con los privilegios del servidor dropbear (usualmente root).

Solution



Actualización de software

Debian Linux 3.1
Source
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0.dsc
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0.diff.gz
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45.orig.tar.gz
Alpha architecture:
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0_alpha.deb
AMD64 architecture:
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0_amd64.deb
ARM
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0_arm.deb
Intel IA-32 architecture:
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0_i386.deb
Intel IA-64 architecture:
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0_ia64.deb
HP Precision architecture:
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0_hppa.deb
Motorola 680x0 architecture:
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0_m68k.deb
Big endian MIPS architecture:
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0_mips.deb
Little endian MIPS architecture:
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0_mipsel.deb
PowerPC architecture:
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0_powerpc.deb
IBM S/390 architecture:
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0_s390.deb
Sun Sparc architecture:
http://security.debian.org/pool/updates/main/d/dropbear/dropbear_0.45-2sarge0_sparc.deb

Standar resources

Property Value
CVE CVE-2005-4178
BID

Other resources

Debian Security Advisory DSA 923-1
http://lists.debian.org/debian-security-announce/debian-security-announce-2005/msg00324.html

Version history

Version Comments Date
1.0 Aviso emitido 2005-12-19
Ministerio de Defensa
CNI
CCN
CCN-CERT