Candidate: CVE-2013-4421 PublicDate: 2013-10-25 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4421 https://secure.ucc.asn.au/hg/dropbear/rev/0bf76f54de6f Description: The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial of service (memory consumption) via a compressed packet that has a large size when it is decompressed. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=726019 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_dropbear: other: https://secure.ucc.asn.au/hg/dropbear/rev/0bf76f54de6f upstream_dropbear: needs-triage lucid_dropbear: ignored (reached end-of-life) precise_dropbear: ignored (reached end-of-life) precise/esm_dropbear: DNE (precise was needs-triage) quantal_dropbear: ignored (reached end-of-life) raring_dropbear: ignored (reached end-of-life) saucy_dropbear: ignored (reached end-of-life) trusty_dropbear: not-affected (2013.59) trusty/esm_dropbear: DNE (trusty was not-affected [2013.59]) utopic_dropbear: ignored (reached end-of-life) vivid_dropbear: ignored (reached end-of-life) vivid/stable-phone-overlay_dropbear: DNE vivid/ubuntu-core_dropbear: DNE wily_dropbear: ignored (reached end-of-life) xenial_dropbear: not-affected (2013.59) yakkety_dropbear: ignored (reached end-of-life) zesty_dropbear: ignored (reached end-of-life) artful_dropbear: ignored (reached end-of-life) bionic_dropbear: not-affected (2013.59) cosmic_dropbear: not-affected (2013.59) devel_dropbear: not-affected (2013.59)