I looked through some Debian and Ubuntu ISOs and didn't notice dropbear installed in the live image. It's likely we are mostly susceptible to this because the live image is used as a loopback mount during normal installation. Many other Debian-based systems would be debootstrapped onto the host.
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Feed Advanced Search
Advanced Search
Advanced Search
Sun, Mar 30
Sun, Mar 30
Tue, Mar 18
Tue, Mar 18
Thanks. I'll see what I can do about reporting this upstream!
Mon, Mar 17
Mon, Mar 17
MITRE has assigned CVE-2025-30095.
Thu, Mar 13
Thu, Mar 13
Looks like it was assigned too restrictively before.
Hi there,
Mon, Mar 10
Mon, Mar 10
Thu, Mar 6
Thu, Mar 6
Is there anyone else we should tag on this ticket?
Tue, Mar 4
Tue, Mar 4
mjones-vsat renamed T7217: Private SSH key reuse in the console server service from test to Key reuse in VyOS Dropbear deployment.