Dropbear SSH update (vulnerability)

Everything about rooting Toons 1 and 2.

Moderators: marcelr, Toonz, TheHogNL, TerrorSource

Dropbear SSH update (vulnerability)

Postby Prutzer » Thu Nov 19, 2020 1:08 pm

Hi all,

I scanned my Toon thermostaat with Nessus Vulnerability scanner. My toon is using dropbear SSH 2015.71 with muliple critical security issues.
Is it safe to upgrade dropbear to a higher version? What is the command for it?

Code: Select all
Dropbear SSH Server < 2016.72 Multiple Vulnerabilities
Description
According to its self-reported version in its banner, Dropbear SSH running on the remote host is prior to 2016.74. It is, therefore, affected by the following vulnerabilities :

- A format string flaw exists due to improper handling of string format specifiers (e.g., %s and %x) in usernames and host arguments. An unauthenticated, remote attacker can exploit this to execute arbitrary code with root privileges. (CVE-2016-7406)

- A flaw exists in dropbearconvert due to improper handling of specially crafted OpenSSH key files. An unauthenticated, remote attacker can exploit this to execute arbitrary code. (CVE-2016-7407)

- A flaw exists in dbclient when handling the -m or -c arguments in scripts. An unauthenticated, remote attacker can exploit this, via a specially crafted script, to execute arbitrary code. (CVE-2016-7408)

- A flaw exists in dbclient or dropbear server if they are compiled with the DEBUG_TRACE option and then run using the -v switch. A local attacker can exploit this to disclose process memory. (CVE-2016-7409)
Solution
Upgrade to Dropbear SSH version 2016.74 or later.
Prutzer
Starting Member
Starting Member
 
Posts: 11
Joined: February 2018

Re: Dropbear SSH update (vulnerability)

Postby TheHogNL » Thu Nov 19, 2020 3:16 pm

I would not care about this. Only if you have opened your SSH port on the firewall from public internet.

There is no new dropbear package for the toon. Compiling a new dropbear for the Toon1 is too much trouble for this.
Member of the Toon Software Collective
User avatar
TheHogNL
Forum Moderator
Forum Moderator
 
Posts: 1729
Joined: August 2017


Return to Toon Rooting

Who is online

Users browsing this forum: No registered users and 1 guest