CVE-2016-7406

critical
Published 2017-03-03 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
10.0
VIR risk
9.8

Description

Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-7406

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://security.gentoo.org/glsa/201702-23

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://secure.ucc.asn.au/hg/dropbear/rev/b66a483f3dcb

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.openwall.com/lists/oss-security/2016/09/15/2

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2016.74-1
debian debianbullseyefixed2016.74-1
debian debianforkyfixed2016.74-1
debian debiansidfixed2016.74-1
debian debiantrixiefixed2016.74-1

Application impact

VendorProductVersionsFixed
dropbear_ssh_projectdropbear_ssh{"endIncluding":"2016.73"}

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.