CVE-2025-47203
CVE-2025-47203
dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used.
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Produtos afetados
Dropbear SSH Project · Dropbear SSHQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://github.com/mkj/dropbear/blob/master/CHANGEShttps://github.com/mkj/dropbear/blob/master/src/cli-main.chttps://lists.debian.org/debian-lts-announce/2025/05/msg00020.htmlhttp://www.openwall.com/lists/oss-security/2025/05/09/4http://www.openwall.com/lists/oss-security/2025/05/12/6http://www.openwall.com/lists/oss-security/2025/05/13/1http://www.openwall.com/lists/oss-security/2025/05/13/10http://www.openwall.com/lists/oss-security/2025/05/13/3