>> Dropbear SSH Server "svr-chansession.c" Buffer Overflow Vulnerability
Title : Dropbear SSH Server "svr-chansession.c" Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2005-2962 CVE ID : CVE-2005-4178
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-19
Technical Description
A vulnerability has been identified in Dropbear SSH Server, which could be exploited by malicious users to execute arbitrary commands. This flaw is due to a buffer overflow error in "svr-chansession.c" when processing specially crafted variables, which could be exploited by authenticated attackers to execute arbitrary commands with "root" privileges.