Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-1099

Опубликовано: 26 фев. 2007
Источник: debian
EPSS Низкий

Описание

dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dropbearfixed0.49-1package
dropbearfixed0.48.1-2etchpackage

Примечания

  • That's a lack of a security feature (strict hostkey checking in openssh

  • termininoloy) and an awkward interface, but not a vulnerability per se

  • Especially as dropbear is specifically labeled a stripped down SSH implementation

EPSS

Процентиль: 81%
0.01626
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks.

nvd
больше 18 лет назад

dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks.

github
больше 3 лет назад

dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks.

EPSS

Процентиль: 81%
0.01626
Низкий