dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dropbear_ssh | Dropbear_ssh_project | * | 0.49 (excluding) |
Dropbear | Ubuntu | dapper | * |
Dropbear | Ubuntu | devel | * |
Dropbear | Ubuntu | edgy | * |
Dropbear | Ubuntu | feisty | * |
Dropbear | Ubuntu | gutsy | * |
Dropbear | Ubuntu | hardy | * |
Dropbear | Ubuntu | intrepid | * |
Dropbear | Ubuntu | jaunty | * |
Dropbear | Ubuntu | karmic | * |