CVE-2016-7409: Infoleak
The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUGTRACE, allows local users to read process memory via the -v argument, related to a failed remote ident.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7409?
CVE-2016-7409 has a severity rating that indicates it can allow local users to exploit the system for unauthorized access to sensitive process memory.
How do I fix CVE-2016-7409?
To fix CVE-2016-7409, you should upgrade Dropbear SSH to version 2016.74 or later, where the vulnerability is patched.
Who is affected by CVE-2016-7409?
CVE-2016-7409 affects local users of Dropbear SSH versions prior to 2016.74 when compiled with DEBUG_TRACE enabled.
What type of vulnerability is CVE-2016-7409?
CVE-2016-7409 is a local privilege escalation vulnerability that allows users to read process memory.
Can CVE-2016-7409 be exploited remotely?
CVE-2016-7409 cannot be exploited remotely as it requires local access to the system.