Medium severity4.7NVD Advisory· Published May 19, 2017· Updated May 13, 2026
CVE-2017-9079
CVE-2017-9079
Description
Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed.
Affected products
2- cpe:2.3:a:dropbear_ssh_project:dropbear_ssh:*:*:*:*:*:*:*:*Range: <2017.75
- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- lists.ucc.gu.uwa.edu.au/pipermail/dropbear/2017q2/001985.htmlnvdMailing ListPatchThird Party Advisory
- www.debian.org/security/2017/dsa-3859nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20191004-0006/nvd
News mentions
0No linked articles in our index yet.