CVE-2013-4421
EPSS 25.9%
Description
The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial of service (memory consumption) via a compressed packet that has a large size when it is decompressed.
How to fix CVE-2013-4421
To remediate CVE-2013-4421, upgrade the affected package to a fixed version below.
- Debian/dropbear—upgrade to 2012.55-1.4 or later
Is CVE-2013-4421 being exploited?
Moderate — EPSS is 25.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2012.55-1.4