CVE-2017-2659

NONE EPSS 71.2%
Published Mar 21, 20197y ago · Modified Jun 17, 20262w ago
Find Similar
Published Mar 21, 2019 7y ago
Last Modified Jun 17, 2026 2w ago

Description

It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.

Threat Intelligence

EPSS Exploit Probability
71.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 2

CWE-209
CWE-287 Improper Authentication Authentication

Affected Products 1

VendorProductVersionRange
dropbear_ssh_projectdropbear_ssh* <2013.59

References 2

  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2659
    Issue TrackingPatchThird Party Advisory
  • secure.ucc.asn.au https://secure.ucc.asn.au/hg/dropbear/rev/d7784616409a#l1.86
    PatchThird Party Advisory

Remediation

  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2659
    Issue TrackingPatchThird Party Advisory
  • secure.ucc.asn.au https://secure.ucc.asn.au/hg/dropbear/rev/d7784616409a#l1.86
    PatchThird Party Advisory