Bugzilla – Bug 970633
VUL-0: CVE-2016-3116: dropbear: Validate X11 forwarding input. Could allow bypass of authorized_keyscommand= restrictions, found by...
Last modified: 2016-03-24 14:12:28 UTC
CVE-2016-3116 - Validate X11 forwarding input. Could allow bypass of authorized_keys command= restrictions, found by github.com/tintinweb. Thanks for Damien Miller for a patch. References: https://matt.ucc.asn.au/dropbear/CHANGES http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-3116 http://seclists.org/oss-sec/2016/q1/593 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-3116.html
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (970633) was mentioned in https://build.opensuse.org/request/show/371343 13.2 / dropbear https://build.opensuse.org/request/show/371346 42.1 / dropbear
This is an autogenerated message for OBS integration: This bug (970633) was mentioned in https://build.opensuse.org/request/show/372675 13.1 / dropbear
released
openSUSE-SU-2016:0874-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 970633 CVE References: CVE-2016-3116 Sources used: openSUSE 13.1 (src): dropbear-2016.72-2.7.1
openSUSE-SU-2016:0882-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 970633 CVE References: CVE-2016-3116 Sources used: openSUSE Leap 42.1 (src): dropbear-2016.72-8.1 openSUSE 13.2 (src): dropbear-2016.72-2.3.1