Debian Security Update DSA-5591-1 libssh - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
30
Reaction score
10
Credits
0
Several vulnerabilities were discovered in libssh, a tiny C SSH library.
CVE-2023-6004
It was reported that using the ProxyCommand or the ProxyJump feature may allow an attacker to inject malicious code through specially crafted hostnames.
CVE-2023-6918
Jack Weinstein reported that missing checks for return values for digests may result in denial of service (application crashes) or usage of uninitialized memory.
CVE-2023-48795
Fabian Baeumer, Marcus Brinkmann and Joerg Schwenk discovered that the SSH protocol is prone to a prefix truncation attack, known as the "Terrapin attack". This attack allows a MITM attacker to effect a limited break of the integrity of the early encrypted SSH transport protocol by sending extra messages prior to the commencement of encryption, and deleting an equal number of consecutive messages immediately after encryption starts.
Details can be found at https://terrapin-attack.com/
https://security-tracker.debian.org/tracker/DSA-5591-1

Continue reading...
 

Members online


Top