[USN-6585-1] libssh2 vulnerability

Severity Medium
Affected Packages 2
CVEs 1

libssh2 could be made to expose sensitive information over the network.

Fabian Bäumer, Marcus Brinkmann, Jörg Schwenk discovered that the SSH
protocol was vulnerable to a prefix truncation attack. If a remote attacker
was able to intercept SSH communications, extension negotiation messages
could be truncated, possibly leading to certain algorithms and features
being downgraded. This issue is known as the Terrapin attack. This update
adds protocol extensions to mitigate this issue.

Package Affected Version
pkg:deb/ubuntu/libssh2-1?distro=mantic < 1.11.0-2ubuntu0.1
pkg:deb/ubuntu/libssh2-1-dev?distro=mantic < 1.11.0-2ubuntu0.1
ID
USN-6585-1
Severity
medium
Severity from
CVE-2023-48795
URL
https://ubuntu.com/security/notices/USN-6585-1
Published
2024-01-15T18:31:03
(8 months ago)
Modified
2024-01-15T18:31:03
(8 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/libssh2-1?distro=mantic ubuntu libssh2-1 < 1.11.0-2ubuntu0.1 mantic
Affected pkg:deb/ubuntu/libssh2-1-dev?distro=mantic ubuntu libssh2-1-dev < 1.11.0-2ubuntu0.1 mantic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...