Debian Dropbear vulnerabilities
23 known vulnerabilities affecting debian/dropbear.
Total CVEs
23
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH5MEDIUM8LOW8
Vulnerabilities
Page 2 of 2
CVE-2025-47203P4MEDIUMCVSS 4.5fixed in dropbear 2022.83-1+deb12u3 (bookworm)2025
CVE-2025-47203 [MEDIUM] CVE-2025-47203: dropbear - dbclient in Dropbear SSH before 2025.88 allows command injection via an untruste...
dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used.
Scope: local
bookworm: resolved (fixed in 2022.83-1+deb12u3)
bullseye: resolved (fixed in 2020.81-3+deb11u3)
forky: resolved (fixed in 2025.88-1)
sid: resolved (fixed in 2025.88-1)
trixie: resolved (fixed in 2025.88-1)
debian
CVE-2016-7409P4LOWCVSS 5.5fixed in dropbear 2016.74-1 (bookworm)2016
CVE-2016-7409 [MEDIUM] CVE-2016-7409: dropbear - The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG...
The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident.
Scope: local
bookworm: resolved (fixed in 2016.74-1)
bullseye: resolved (fixed in 2016.74-1)
forky: resolved (fixed in 2016.74-1)
sid: resolved (fixed in 2016.74-1)
trixie: resolved
debian
CVE-2017-9079P4MEDIUMCVSS 4.7fixed in dropbear 2016.74-5 (bookworm)2017
CVE-2017-9079 [MEDIUM] CVE-2017-9079: dropbear - Dropbear before 2017.75 might allow local users to read certain files as root, i...
Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed.
Scope: local
bookworm: resolved (fixed in 2016.74-5)
bullseye: resolved (fixed in 2016.74-5)
forky: resolved (fixed i
debian
← Previous2 / 2