[FREEBSD:91955195-9EBB-11EE-BC14-A703705DB3A6] putty -- add protocol extension against 'Terrapin attack'

Severity Medium
Affected Packages 2
CVEs 1

Simon Tatham reports:

    PuTTY version 0.80 [contains] one security fix [...] for a newly discovered security issue known as the 'Terrapin'

attack, also numbered CVE-2023-48795. The issue affects widely-used
OpenSSH extensions to the SSH protocol: the ChaCha20+Poly1305
cipher system, and 'encrypt-then-MAC' mode.
In order to benefit from the fix, you must be using a fixed version
of PuTTY and a server with the fix, so that they can agree to
adopt a modified version of the protocol. [...]

Package Affected Version
pkg:freebsd/putty-nogtk < 0.80
pkg:freebsd/putty < 0.80
ID
FREEBSD:91955195-9EBB-11EE-BC14-A703705DB3A6
Severity
medium
Severity from
CVE-2023-48795
URL
http://vuxml.freebsd.org/freebsd/91955195-9ebb-11ee-bc14-a703705db3a6.html
Published
2023-10-16T00:00:00
(11 months ago)
Modified
2023-12-19T00:00:00
(9 months ago)
Rights
FreeBSD VuXML Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:freebsd/putty-nogtk putty-nogtk < 0.80
Affected pkg:freebsd/putty putty < 0.80
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...