The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-05-19T14:00:00

Updated: 2024-08-05T16:55:22.121Z

Reserved: 2017-05-19T00:00:00

Link: CVE-2017-9078

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-05-19T14:29:00.280

Modified: 2022-07-11T17:11:02.163

Link: CVE-2017-9078

cve-icon Redhat

No data.