Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed.
CVSS Details
- CVSS 3.0 Base Score: 4.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dropbear | Aug 30, 2017 | May 19, 2017 |
| Debian | — | Upgrade dropbear | May 20, 2017 | May 19, 2017 |
| Freebsd | — | Upgrade dropbear | Jul 4, 2017 | Jul 3, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | May 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub