7.5
CVSSv2

CVE-2007-1099

Published: 26/02/2007 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

dbclient in Dropbear SSH client prior to 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote malicious users to conduct man-in-the-middle attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dropbear ssh project dropbear ssh

Vendor Advisories

Debian Bug report logs - #412899 CVE-2007-1099: dropbear dbclient insufficient warning on hostkey mismatch Package: dropbear; Maintainer for dropbear is Guilhem Moulin <guilhem@debianorg>; Source for dropbear is src:dropbear (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Wed, 28 Feb 2007 20 ...