{"id":"MGASA-2013-0318","summary":"Updated dropbear packages fix CVE-2013-4421","details":"Updated dropbear package fixes security vulnerability:\n\nPossible memory exhaustion denial of service due to the size of\ndecompressed payloads in dropbear before 2013.59 (CVE-2013-4421).\n\nInconsistent delays in authorization failures could be used to\ndisclose the existence of valid user accounts in dropbear before\n2013.59 (CVE-2013-4434).\n","modified":"2026-04-16T06:26:02.120664600Z","published":"2013-10-25T21:10:23Z","upstream":["CVE-2013-4421","CVE-2013-4434"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2013-0318.html"},{"type":"WEB","url":"https://matt.ucc.asn.au/dropbear/CHANGES"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2013/10/11/4"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=11442"}],"affected":[{"package":{"name":"dropbear","ecosystem":"Mageia:2","purl":"pkg:rpm/mageia/dropbear?arch=source&distro=mageia-2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2013.59-1.mga2"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0318.json"}},{"package":{"name":"dropbear","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/dropbear?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2013.59-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0318.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}