Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <c26387d6-44a0-46a4-9673-a1d14624c465@gmail.com>
Date: Tue, 13 May 2025 12:49:44 +0200
From: Albert Veli <albert.veli@...il.com>
To: Matt Johnston <matt@....asn.au>, oss-security@...ts.openwall.com
Subject: Re: Dropbear SSH 2025.88 fixes CVE-2025-47203

Thanks, this worked.

On 2025-05-13 02:47, Matt Johnston wrote:
> dbclient 'localhost,|touch 123 '
>
Although I have a custom CLI as login shell in /etc/passwd, but if I 
change it to /bin/sh then it works.
>> 2. Both dbclient and ssh are symlinks to the same dropbear binary.
>> Does this CVE apply equally to both, or is it specific to dbclient?
>
> It applies to both.
Thanks. That means I am vulnerable (except for the login shell part that 
complicates it).

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.