Matt Johnston Dropbear SSH 远程拒绝服务漏洞
CNNVD-ID编号 | CNNVD-200603-228 | CVE编号 | CVE-2006-1206 |
发布时间 | 2006-03-13 | 更新时间 | 2006-03-15 |
漏洞类型 | 其他 | 漏洞来源 | Discovery of this vulnerability is credited to Pablo Fernandez. |
危险等级 | 中危 | 威胁类型 | 远程 |
厂商 | matt_johnston |
漏洞介绍
Matt Johnston Dropbear SSH 服务器0.47及其早期版本,当使用在嵌入式Linux设备和一般目的操作系统上时,可以让远程攻击者通过以下途径制造一个拒绝服务(连接槽用完): 超过MAX_UNAUTH_CLIENTS中定义值30的大量连接尝试。
漏洞补丁
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Dropbear SSH Server 0.28
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.29
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.30
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.31
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.32
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.33
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.34
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.35
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.36
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.37
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.38
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.39
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.40
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.41
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.42
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.43
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.44
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.45
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.46
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
Dropbear SSH Server 0.47
Dropbear dropbear-0.48.tar.gz
http://matt.ucc.asn.au/dropbear/dropbear-0.48.tar.gz
参考网址
来源: BID
名称: 17024
链接:http://www.securityfocus.com/bid/17024
来源: XF
名称: dropbear-connection-dos(25075)
链接:http://xforce.iss.net/xforce/xfdb/25075
来源: BUGTRAQ
名称: 20060307 Dropbear SSH server Denial of Service
链接:http://www.securityfocus.com/archive/1/archive/1/426999/100/0/threaded
受影响实体
Matt_johnston Dropbear_ssh_server:0.47 Matt_johnston Dropbear_ssh_server:0.46 Matt_johnston Dropbear_ssh_server:0.45 Matt_johnston Dropbear_ssh_server:0.44 Matt_johnston Dropbear_ssh_server:0.43信息来源
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200603-228

评论