CVE-2017-9078: Double Free
Published May 19, 2017
·Updated
The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled.
Affected Software
4 affected components
Dropbear Ssh Project Dropbear Ssh<2017.75
Debian Debian Linux=8.0
NetApp H410c Firmware
NetApp H410c
Remediation
Event History
May 19, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9078?
CVE-2017-9078 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2017-9078?
To fix CVE-2017-9078, update to Dropbear version 2017.75 or later.
3
What systems are affected by CVE-2017-9078?
CVE-2017-9078 affects Dropbear versions prior to 2017.75, specifically on Debian 8.0 and certain NetApp firmware.
4
What is the impact of CVE-2017-9078?
CVE-2017-9078 enables post-authentication root remote code execution, which could lead to complete system compromise.
5
Is CVE-2017-9078 exploitable without authentication?
No, CVE-2017-9078 requires authentication to exploit.