![]() |
|
Message-ID: <c26387d6-44a0-46a4-9673-a1d14624c465@gmail.com> Date: Tue, 13 May 2025 12:49:44 +0200 From: Albert Veli <albert.veli@...il.com> To: Matt Johnston <matt@....asn.au>, oss-security@...ts.openwall.com Subject: Re: Dropbear SSH 2025.88 fixes CVE-2025-47203 Thanks, this worked. On 2025-05-13 02:47, Matt Johnston wrote: > dbclient 'localhost,|touch 123 ' > Although I have a custom CLI as login shell in /etc/passwd, but if I change it to /bin/sh then it works. >> 2. Both dbclient and ssh are symlinks to the same dropbear binary. >> Does this CVE apply equally to both, or is it specific to dbclient? > > It applies to both. Thanks. That means I am vulnerable (except for the login shell part that complicates it).
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.