CVE-2004-2486: High severity Dropbear Ssh Project Dropbear Ssh vulnerability
Published Dec 31, 2004
·Updated
The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.
Affected Software
1 affected component
Dropbear Ssh Project Dropbear Ssh<0.43
Event History
Dec 31, 2004
CVE Published
05:00 AM
Oct 25, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2486?
CVE-2004-2486 is classified as a medium severity vulnerability due to its potential to allow remote attackers to gain unauthorized access.
2
How do I fix CVE-2004-2486?
To fix CVE-2004-2486, upgrade Dropbear SSH Server to version 0.43 or later.
3
What are the consequences of exploiting CVE-2004-2486?
Exploiting CVE-2004-2486 may allow remote attackers to execute unauthorized commands on affected systems.
4
Which versions of Dropbear SSH are affected by CVE-2004-2486?
Dropbear SSH versions prior to 0.43 are affected by CVE-2004-2486.
5
Is there any workaround for CVE-2004-2486?
There are no known workarounds for CVE-2004-2486; upgrading to the latest version is the recommended solution.