First published: Fri Mar 03 2017(Updated: )
The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dropbear SSH | <=2016.73 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7407 has a high severity rating due to the potential for arbitrary code execution.
To fix CVE-2016-7407, update Dropbear SSH to version 2016.74 or later.
CVE-2016-7407 affects all versions of Dropbear SSH prior to 2016.74.
Attackers can execute arbitrary code by providing a specially crafted OpenSSH key file.
Yes, CVE-2016-7407 can be exploited remotely if the vulnerable version of Dropbear SSH is accessible over a network.