English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Debian update for dropbear


Secunia ID

SA48929

CVE-ID

CVE-2012-0920

Release Date

25 Apr 2012

Criticality

Less Critical

Solution Status

Vendor Patch

Where

From remote

Impact
Privilege escalation

This covers vulnerabilities where a user is able to conduct certain tasks with the privileges of other users or administrative users.

This typically includes cases where a local user on a client or server system can gain access to the administrator or root account thus taking full control of the system.

Description

Debian has issued an update for dropbear. This fixes a vulnerability, which can be exploited by malicious users to gain escalated privileges.

For more information:
SA48147

Solution

Apply updated packages via the apt-get package manager.

Original Advisory

DSA-2456-1:
http://www.us.debian.org/security/2012/dsa-2456