Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2659

Опубликовано: 21 мар. 2019
Источник: debian
EPSS Низкий

Описание

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dropbearfixed2013.60-1package

Примечания

  • https://hg.ucc.asn.au/dropbear/rev/d7784616409a#l1.86

EPSS

Процентиль: 51%
0.00275
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 7 лет назад

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

CVSS3: 5.3
nvd
почти 7 лет назад

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

CVSS3: 7.5
github
больше 3 лет назад

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

EPSS

Процентиль: 51%
0.00275
Низкий