CVE-2020-36254

Name
CVE-2020-36254
Description
scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/mkj/dropbear/commit/8f8a3dff705fad774a10864a2e3dbcfa9779ceff

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:dropbear_project:dropbear:*:*:*:*:*:*:*:* dropbear >= None < 2020.79
cpe:2.3:a:dropbear_ssh_project:dropbear_ssh:*:*:*:*:*:*:*:* dropbear_ssh >= None < 2020.79

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
dropbear 3.12-main 2019.78-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
dropbear 3.11-main 2019.78-r1 Natanael Copa <ncopa@alpinelinux.org> fixed
dropbear 3.10-main 2019.78-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable