Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2659

Опубликовано: 21 мар. 2019
Источник: debian

Описание

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dropbearfixed2013.60-1package

Примечания

  • https://hg.ucc.asn.au/dropbear/rev/d7784616409a#l1.86

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

CVSS3: 5.3
nvd
больше 7 лет назад

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

CVSS3: 7.5
github
больше 4 лет назад

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.