[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-5591-1 libssh -- libssh

ID: oval:org.secpod.oval:def:96944Date: (C)2024-01-22   (M)2024-04-29
Class: PATCHFamily: unix




Several vulnerabilities were discovered in libssh, a tiny C SSH library. CVE-2023-6004 It was reported that using the ProxyCommand or the ProxyJump feature may allow an attacker to inject malicious code through specially crafted hostnames. CVE-2023-6918 Jack Weinstein reported that missing checks for return values for digests may result in denial of service or usage of uninitialized memory. CVE-2023-48795 Fabian Baeumer, Marcus Brinkmann and Joerg Schwenk discovered that the SSH protocol is prone to a prefix truncation attack, known as the Terrapin attack. This attack allows a MITM attacker to effect a limited break of the integrity of the early encrypted SSH transport protocol by sending extra messages prior to the commencement of encryption, and deleting an equal number of consecutive messages immediately after encryption starts. Details can be found at https://terrapin-attack.com/

Platform:
Linux Mint 6
Linux Mint 5
Product:
libssh-gcrypt-dev
libssh-4
libssh-gcrypt-4
libssh-dev
libssh-doc
Reference:
DSA-5591-1
CVE-2023-6004
CVE-2023-6918
CVE-2023-48795
CVE    3
CVE-2023-6918
CVE-2023-6004
CVE-2023-48795
CPE    6
cpe:/a:libssh:libssh-dev
cpe:/a:libssh-gcrypt-4:libssh-gcrypt-4
cpe:/a:libssh:libssh:4
cpe:/a:libssh-doc:libssh-doc
...

© SecPod Technologies