src icon indicating copy to clipboard operation
src copied to clipboard

CVE-2025-61985 (Low) detected in freebsd-srcrelease/14.3.0-p2

Open mend-bolt-for-github[bot] opened this issue 1 month ago • 0 comments

CVE-2025-61985 - Low Severity Vulnerability

Vulnerable Library - freebsd-srcrelease/14.3.0-p2

The FreeBSD src tree publish-only repository. Experimenting with 'simple' pull requests....

Library home page: https://github.com/freebsd/freebsd-src.git

Found in base branches: stable/3.2, master

Vulnerable Source Files (1)

Vulnerability Details

ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

Publish Date: 2025-10-06

URL: CVE-2025-61985

CVSS 3 Score Details (3.6)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: High
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2025-10-06

Fix Resolution: https://github.com/openssh/openssh-portable.git - V_10_1_P1


Step up your Open Source Security Game with Mend here