DEBIAN-CVE-2025-68920

Source
https://security-tracker.debian.org/tracker/CVE-2025-68920
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68920.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-68920
Upstream
  • CVE-2025-68920
Published
2025-12-24T22:15:43.550Z
Modified
2025-12-25T11:15:27.267308Z
Severity
  • 8.9 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L CVSS Calculator
Summary
[none]
Details

C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary files from the local system.

References

Affected packages

Debian:11 / ckermit

Package

Name
ckermit
Purl
pkg:deb/debian/ckermit?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other
305~alpha02-1
305~alpha04-1
305~alpha05-1
305~alpha06-1
305~alpha07-1
400~beta05-1
400~beta06-1
402~beta08-1
404~beta09-1
405~beta10-1
405~beta10-2~bpo12+1
405~beta10-2
414~beta11-1
414~beta11-2
414~beta11-3~bpo12+1
414~beta11-3
416~beta12-1
416~beta12-2
416~beta12-3~bpo13+1
416~beta12-3
416~beta12-4
416~beta12-5
408~beta11.*
408~beta11.20240207-1~bpo12+1
408~beta11.20240207-1
416~beta12-1.*
416~beta12-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68920.json"

Debian:12 / ckermit

Package

Name
ckermit
Purl
pkg:deb/debian/ckermit?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other
402~beta08-1
404~beta09-1
405~beta10-1
405~beta10-2~bpo12+1
405~beta10-2
414~beta11-1
414~beta11-2
414~beta11-3~bpo12+1
414~beta11-3
416~beta12-1
416~beta12-2
416~beta12-3~bpo13+1
416~beta12-3
416~beta12-4
416~beta12-5
408~beta11.*
408~beta11.20240207-1~bpo12+1
408~beta11.20240207-1
416~beta12-1.*
416~beta12-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68920.json"

Debian:13 / ckermit

Package

Name
ckermit
Purl
pkg:deb/debian/ckermit?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other
416~beta12-1
416~beta12-2
416~beta12-3~bpo13+1
416~beta12-3
416~beta12-4
416~beta12-5
416~beta12-1.*
416~beta12-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68920.json"

Debian:14 / ckermit

Package

Name
ckermit
Purl
pkg:deb/debian/ckermit?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
416~beta12-5

Affected versions

Other
416~beta12-1
416~beta12-2
416~beta12-3~bpo13+1
416~beta12-3
416~beta12-4
416~beta12-1.*
416~beta12-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68920.json"