src
src copied to clipboard
CVE-2025-61985 (Low) detected in freebsd-srcrelease/14.3.0-p2
CVE-2025-61985 - Low Severity Vulnerability
Vulnerable Library - freebsd-srcrelease/14.3.0-p2
The FreeBSD src tree publish-only repository. Experimenting with 'simple' pull requests....
Library home page: https://github.com/freebsd/freebsd-src.git
Found in base branches: stable/3.2, master
Vulnerable Source Files (1)
Vulnerability Details
ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.
Publish Date: 2025-10-06
URL: CVE-2025-61985
CVSS 3 Score Details (3.6)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: High
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2025-10-06
Fix Resolution: https://github.com/openssh/openssh-portable.git - V_10_1_P1
Step up your Open Source Security Game with Mend here