CVE-2016-7406 PUBLISHED

Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.

EPSS 25.33% · 96.1th percentile

Risk Scores

EPSS Score
25.33%
96.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSdropbear0, 2014.65-1ubuntu2, 2015.68-1

Timeline

References

Open in Interactive Console →