[USN-6589-1] FileZilla vulnerability

Severity Medium
Affected Packages 6
CVEs 1

FileZilla could be made to expose sensitive information over the network.

Fabian Baeumer, Marcus Brinkmann and Joerg Schwenk discovered that the SSH
protocol used in FileZilla is prone to a prefix truncation attack, known as
the "Terrapin attack". A remote attacker could use this issue to downgrade or
disable some security features and obtain sensitive information.

ID
USN-6589-1
Severity
medium
Severity from
CVE-2023-48795
URL
https://ubuntu.com/security/notices/USN-6589-1
Published
2024-01-18T17:55:52
(8 months ago)
Modified
2024-01-18T17:55:52
(8 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/filezilla?distro=mantic ubuntu filezilla < 3.65.0-3ubuntu0.1 mantic
Affected pkg:deb/ubuntu/filezilla?distro=jammy ubuntu filezilla < 3.58.0-1ubuntu0.1 jammy
Affected pkg:deb/ubuntu/filezilla?distro=focal ubuntu filezilla < 3.46.3-1ubuntu0.1 focal
Affected pkg:deb/ubuntu/filezilla-common?distro=mantic ubuntu filezilla-common < 3.65.0-3ubuntu0.1 mantic
Affected pkg:deb/ubuntu/filezilla-common?distro=jammy ubuntu filezilla-common < 3.58.0-1ubuntu0.1 jammy
Affected pkg:deb/ubuntu/filezilla-common?distro=focal ubuntu filezilla-common < 3.46.3-1ubuntu0.1 focal
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...