CVE-2017-2659Information Exposure via Error Message in SSH Project Dropbear SSH

Severity
7.5HIGHNVD
EPSS
0.3%
top 48.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 13

Description

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/dropbear< dropbear 2013.60-1 (bookworm)
Debiandropbear_ssh_project/dropbear_ssh< 2013.60-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m7fh-9pv8-fwc2: It was found that dropbear before version 20132022-05-13
OSV
CVE-2017-2659: It was found that dropbear before version 20132019-03-21

📋Vendor Advisories

1
Debian
CVE-2017-2659: dropbear - It was found that dropbear before version 2013.59 with GSSAPI leaks whether give...2017

💬Community

2
Bugzilla
CVE-2017-7594 libtiff: Memory leak in OJPEGReadHeaderInfoSecTablesDcTable function2017-04-11
Bugzilla
CVE-2017-2659 dropbear: Information leak when given invalid username2017-03-20