Is there a fix for X8DTU-F for SSH Dropbear issue?
The following CVEs target the SSH server dropbear.
dropbear SSH version is prior to 2016.74
CVE vulnerabilities:
- A format string flaw exists due to improper handling of string format specifiers
(e.g., %s and %x) in usernames and host arguments. An
unauthenticated, remote attacker can exploit this to execute arbitrary code
with root privileges. (CVE-2016-7406)
- A flaw exists in dropbearconvert due to improper handling of specially
crafted OpenSSH key files. An unauthenticated, remote attacker can exploit
this to execute arbitrary code. (CVE-2016-7407)
- A flaw exists in dbclient when handling the -m or -c arguments in scripts.
An unauthenticated, remote attacker can exploit this, via a specially crafted
script, to execute arbitrary code. (CVE-2016-7408)
- A flaw exists in dbclient or dropbear server if they are compiled with the
DEBUG_TRACE option and then run using the -v switch. A local attacker can
exploit this to disclose process memory. (CVE-2016-7409)
Would it be possible to update the ssh to a later version which would resolve these CVEs?
Please contact support for firmware 3.15 and above to fix dropbear issue.