CVE-2025-68920

NameCVE-2025-68920
DescriptionC-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary files from the local system.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1123025

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ckermit (PTS)bullseye305~alpha02-1vulnerable
bookworm402~beta08-1vulnerable
trixie416~beta12-1vulnerable
forky, sid416~beta12-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ckermitsource(unstable)416~beta12-51123025

Notes

[trixie] - ckermit <no-dsa> (Minor issue; documented; can be fixed via point release)
[bookworm] - ckermit <no-dsa> (Minor issue; documented; can be fixed via point release)
[bullseye] - ckermit <postponed> (Minor issue; documented)
https://github.com/KermitProject/ckermit/pull/20

Search for package or bug name: Reporting problems