Security Advisories (3)
CVE-2025-40913 (2025-07-16)

Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net::DropbearĀ embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.

CVE-2019-12953 (2020-12-30)

Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599.

CVE-2016-6129 (2017-02-13)

The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equal to the ASN.1 encoded data length, which makes it easier for remote attackers to forge RSA signatures or public certificates by leveraging a Bleichenbacher signature forgery attack.

NAME

Net::Dropbear - Use Dropbear SSH inside of perl

DESCRIPTION

This is a container package. You want one of the sub packages:

Net::Dropbear::SSHd - Embed and control a Dropbear SSH server inside of perl
Net::Dropbear::SSH - Embed and control a Dropbear SSH client inside of perl (Not implemented yet)

AUTHOR

Jon Gentle <atrodo@cpan.org>

COPYRIGHT

Copyright 2015-2016 Jon Gentle

LICENSE

This is free software. You may redistribute copies of it under the terms of the Artistic License 2 as published by The Perl Foundation.