4 ms·
Dropbear claims to be RFC-compliant, but isnt. Proof here: https://www.cvedetails.com/cve/CVE-2021-36369/ https://www.cvedetails.com/cve/CVE-2021-36369/ TinySS
by Columbo818 3y ago
Dropbear claims to be RFC-compliant, but isnt.
Proof here: https://www.cvedetails.com/cve/CVE-2021-36369/ https://www.cvedetails.com/cve/CVE-2021-36369/
TinySSH doesnt claim to be compliant, and isnt.
Does less in exchange for a reduced attack surface.
- mkj 3y agoThat CVE is a UI confusion issue in the client, I'm not sure exactly what bit the reporter thought was non-RFC compliant.