The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-05-19T14:00:00

Updated: 2024-08-05T16:55:22.121Z

Reserved: 2017-05-19T00:00:00

Link: CVE-2017-9078

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-05-19T14:29:00.280

Modified: 2024-11-21T03:35:17.110

Link: CVE-2017-9078

cve-icon Redhat

No data.