[Git][security-tracker-team/security-tracker][master] Reference writeup for CVE-2025-61984

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Oct 13 08:45:44 BST 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
178933bf by Salvatore Bonaccorso at 2025-10-13T09:44:49+02:00
Reference writeup for CVE-2025-61984

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2178,6 +2178,7 @@ CVE-2025-61984 (ssh in OpenSSH before 10.1 allows control characters in username
 	[bookworm] - openssh <no-dsa> (Minor issue)
 	[bullseye] - openssh <postponed> (Minor issue; can be fixed in next update)
 	NOTE: https://www.openwall.com/lists/oss-security/2025/10/06/1
+	NOTE: https://dgl.cx/2025/10/bash-a-newline-ssh-proxycommand-cve-2025-61984
 CVE-2025-61778 (Akka.NET is a .NET port of the Akka project from the Scala / Java comm ...)
 	NOT-FOR-US: Akka.NET
 CVE-2025-61777 (Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/178933bfb5d9ff1878ccd88deb2b1b761e7c9cf7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/178933bfb5d9ff1878ccd88deb2b1b761e7c9cf7
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251013/bbc95371/attachment.htm>


More information about the debian-security-tracker-commits mailing list