Lucene search

K
archlinuxArch LinuxASA-201603-19
HistoryMar 14, 2016 - 12:00 a.m.

dropbear: command injection

2016-03-1400:00:00
Arch Linux
lists.archlinux.org
50

EPSS

0.028

Percentile

90.7%

A vulnerability was found in a way dropbear processed X11 forwarding
input. By using a specially crafted request, an attacker could bypass
the authorized_keys command restrictions.

xauth is run under the user’s privilege, so this vulnerability offers no
additional access to unrestricted accounts, but could circumvent key or
account restrictions such as sshd_config ForceCommand, authorized_keys
command="…" or restricted shells.

OSVersionArchitecturePackageVersionFilename
anyanyanydropbear< 2016.72-1UNKNOWN