CVE-2012-0920

N/A Unknown
Published: June 05, 2012 Modified: April 29, 2026
View on NVD

Description

Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote authenticated users to execute arbitrary code and bypass command restrictions via multiple crafted command requests, related to "channels concurrency."

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://matt.ucc.asn.au/dropbear/CHANGES
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/48147
Source: cve@mitre.org
Third Party Advisory
http://secunia.com/advisories/48929
Source: cve@mitre.org
Third Party Advisory
http://www.debian.org/security/2012/dsa-2456
Source: cve@mitre.org
Third Party Advisory
http://www.osvdb.org/79590
Source: cve@mitre.org
Broken Link
http://www.securityfocus.com/bid/52159
Source: cve@mitre.org
Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/73444
Source: cve@mitre.org
Third Party Advisory VDB Entry
https://secure.ucc.asn.au/hg/dropbear/rev/818108bf7749
Source: cve@mitre.org
Vendor Advisory
https://www.mantor.org/~northox/misc/CVE-2012-0920.html
Source: cve@mitre.org
Third Party Advisory
http://matt.ucc.asn.au/dropbear/CHANGES
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/48147
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://secunia.com/advisories/48929
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.debian.org/security/2012/dsa-2456
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.osvdb.org/79590
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://www.securityfocus.com/bid/52159
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/73444
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
https://secure.ucc.asn.au/hg/dropbear/rev/818108bf7749
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
https://www.mantor.org/~northox/misc/CVE-2012-0920.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

18 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
6.5%
93th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

debian dropbear_ssh_project