Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-948-1 dropbear security update
Debian DSA Debian DSA DSA-3859-1 dropbear security update
EUVD EUVD EUVD-2017-18018 Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T16:55:21.880Z

Reserved: 2017-05-19T00:00:00

Link: CVE-2017-9079

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-05-19T14:29:00.310

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-9079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses