Back to Database
Status published
High
CVE-2004-2486
The DSS verification code in Dropbear SSH Server before 0.43...
Vulnerability Description
The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-2486
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40490
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml
- http://www.osvdb.org/8137
- http://secunia.com/advisories/12153
- http://matt.ucc.asn.au/dropbear/CHANGES
- http://www.vupen.com/english/advisories/2008/0543
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16810
- http://secunia.com/advisories/28935
- http://www.securityfocus.com/bid/10803
More from dropbear ssh project
View All →CVE-2021-36369
An issue was discovered in Dropbear through 2020.81. Due to...
Unknown
0
CVE-2020-36254
scp.c in Dropbear before 2020.79 mishandles the filename of ....
Unknown
0
CVE-2019-12953
Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that...
Medium
5.3
CVE-2017-9079
Dropbear before 2017.75 might allow local users to read certain...
Medium
4.7
CVE-2017-9078
The server in Dropbear before 2017.75 might allow post-authentication root...
High
8.8
Affected Vendor
dropbear ssh project
View all reports →Affected Software
dropbear ssh
Vulnerable Versions:
0
Timeline
Official Publish:
October 25th, 2005
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.