File tree Expand file tree Collapse file tree 3 files changed +34
-1
lines changed
Expand file tree Collapse file tree 3 files changed +34
-1
lines changed Original file line number Diff line number Diff line change 1+ 2025.88 - 7 May 2025
2+
3+ - Security: Don't allow dbclient hostname arguments to be interpreted
4+ by the shell.
5+
6+ dbclient hostname arguments with a comma (for multihop) would be
7+ passed to the shell which could result in running arbitrary shell
8+ commands locally. That could be a security issue in situations
9+ where dbclient is passed untrusted hostname arguments.
10+
11+ Now the multihop command is executed directly, no shell is involved.
12+ Thanks to Marcin Nowak for the report, tracked as CVE-2025-47203
13+
14+ - Fix compatibility for htole64 and htole32, regression in 2025.87
15+ Patch from Peter Fichtner to work with old GCC versions, and
16+ patch from Matt Robinson to check different header files.
17+
18+ - Fix building on older compilers or libc that don't support
19+ static_assert(). Regression in 2025.87
20+
21+ - Support ~R in the client to force a key re-exchange.
22+
23+ - Improve strict KEX handling. Dropbear previously would allow other
24+ packets at the end of key exchange prior to receiving the remote
25+ peer's NEWKEYS message, which should be forbidden by strict KEX.
26+ Reported by Fabian Bäumer.
27+
1282025.87 - 5 March 2025
229
330Note >> for compatibility/configuration changes
Original file line number Diff line number Diff line change 1+ dropbear (2025.88-0.1) unstable; urgency=low
2+
3+ * New upstream release.
4+
5+ -- Matt Johnston <matt@ucc.asn.au> Wed, 7 May 2025 22:51:57 +0800
6+
17dropbear (2025.87-0.1) unstable; urgency=low
28
39 * New upstream release.
Original file line number Diff line number Diff line change 44 *******************************************************************/
55
66#ifndef DROPBEAR_VERSION
7- #define DROPBEAR_VERSION "2025.87 "
7+ #define DROPBEAR_VERSION "2025.88 "
88#endif
99
1010/* IDENT_VERSION_PART is the optional part after "SSH-2.0-dropbear". Refer to RFC4253 for requirements. */
You can’t perform that action at this time.
0 commit comments