[USN-6561-1] libssh vulnerability

Severity Medium
Affected Packages 20
CVEs 1

A security issue was fixed in libssh.

Fabian Bäumer, Marcus Brinkmann, Jörg Schwenk discovered that the SSH
protocol was vulnerable to a prefix truncation attack. If a remote attacker
was able to intercept SSH communications, extension negotiation messages
could be truncated, possibly leading to certain algorithms and features
being downgraded. This issue is known as the Terrapin attack. This update
adds protocol extensions to mitigate this issue.

ID
USN-6561-1
Severity
medium
Severity from
CVE-2023-48795
URL
https://ubuntu.com/security/notices/USN-6561-1
Published
2023-12-19T13:08:22
(9 months ago)
Modified
2023-12-19T13:08:22
(9 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/libssh-gcrypt-dev?distro=mantic ubuntu libssh-gcrypt-dev < 0.10.5-3ubuntu1.1 mantic
Affected pkg:deb/ubuntu/libssh-gcrypt-dev?distro=lunar ubuntu libssh-gcrypt-dev < 0.10.4-2ubuntu0.2 lunar
Affected pkg:deb/ubuntu/libssh-gcrypt-dev?distro=jammy ubuntu libssh-gcrypt-dev < 0.9.6-2ubuntu0.22.04.2 jammy
Affected pkg:deb/ubuntu/libssh-gcrypt-dev?distro=focal ubuntu libssh-gcrypt-dev < 0.9.3-2ubuntu2.4 focal
Affected pkg:deb/ubuntu/libssh-gcrypt-4?distro=mantic ubuntu libssh-gcrypt-4 < 0.10.5-3ubuntu1.1 mantic
Affected pkg:deb/ubuntu/libssh-gcrypt-4?distro=lunar ubuntu libssh-gcrypt-4 < 0.10.4-2ubuntu0.2 lunar
Affected pkg:deb/ubuntu/libssh-gcrypt-4?distro=jammy ubuntu libssh-gcrypt-4 < 0.9.6-2ubuntu0.22.04.2 jammy
Affected pkg:deb/ubuntu/libssh-gcrypt-4?distro=focal ubuntu libssh-gcrypt-4 < 0.9.3-2ubuntu2.4 focal
Affected pkg:deb/ubuntu/libssh-doc?distro=mantic ubuntu libssh-doc < 0.10.5-3ubuntu1.1 mantic
Affected pkg:deb/ubuntu/libssh-doc?distro=lunar ubuntu libssh-doc < 0.10.4-2ubuntu0.2 lunar
Affected pkg:deb/ubuntu/libssh-doc?distro=jammy ubuntu libssh-doc < 0.9.6-2ubuntu0.22.04.2 jammy
Affected pkg:deb/ubuntu/libssh-doc?distro=focal ubuntu libssh-doc < 0.9.3-2ubuntu2.4 focal
Affected pkg:deb/ubuntu/libssh-dev?distro=mantic ubuntu libssh-dev < 0.10.5-3ubuntu1.1 mantic
Affected pkg:deb/ubuntu/libssh-dev?distro=lunar ubuntu libssh-dev < 0.10.4-2ubuntu0.2 lunar
Affected pkg:deb/ubuntu/libssh-dev?distro=jammy ubuntu libssh-dev < 0.9.6-2ubuntu0.22.04.2 jammy
Affected pkg:deb/ubuntu/libssh-dev?distro=focal ubuntu libssh-dev < 0.9.3-2ubuntu2.4 focal
Affected pkg:deb/ubuntu/libssh-4?distro=mantic ubuntu libssh-4 < 0.10.5-3ubuntu1.1 mantic
Affected pkg:deb/ubuntu/libssh-4?distro=lunar ubuntu libssh-4 < 0.10.4-2ubuntu0.2 lunar
Affected pkg:deb/ubuntu/libssh-4?distro=jammy ubuntu libssh-4 < 0.9.6-2ubuntu0.22.04.2 jammy
Affected pkg:deb/ubuntu/libssh-4?distro=focal ubuntu libssh-4 < 0.9.3-2ubuntu2.4 focal
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...