CVE-2013-4421: Dropbear SSH Decompress DoS Vulnerability

CVE ID

CVE-2013-4421

DESCRIPTION

The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial of service (memory consumption) via a compressed packet that has a large size when it is decompressed.

Unitrends assessment: NOT EXPOSED

The dropbear ssh server is not the same as the openssh-server package. Our CentOS installations use the openssh-server package instead.

RESOLUTION

Fixed in dropbear-2013.59-1.el6 package from the Fedora EPEL repository.

LINK TO ADVISORIES

Have more questions?

Contact us

Was this article helpful?
0 out of 0 found this helpful

Provide feedback for the Documentation team!

Browse this section