| Summary: | CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack) - putty | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Marja Van Waes <marja11> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | critical | ||
| Priority: | Normal | CC: | andrewsfarm, brtians1, herman.viaene, lewyssmith, marja11, nicolas.salguero, pkg-bugs, security, sysadmin-bugs, yvesbrungard |
| Version: | 9 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA9-64-OK | ||
| Source RPM: | putty | CVE: | CVE-2023-48795 |
| Status comment: | |||
| Bug Depends on: | |||
| Bug Blocks: | 32641 | ||
|
Description
Marja Van Waes
2023-12-31 17:56:08 CET
@ daviddavid Since you fixed this for cauldron, I assume you're OK with fixing it in Mageia 9, too Assignee:
bugsquad =>
geiger.david68210
Marja Van Waes
2024-01-02 12:00:49 CET
CVE:
(none) =>
CVE-2023-48795 An update is submitted: RPMS: putty-0.80-1.mga9 Source:putty-0.80-1.mga9 Assignee:
geiger.david68210 =>
qa-bugs (In reply to papoteur from comment #2) > Source:putty-0.80-1.mga9 Advisory with SRPM from comment 2 added to SVN. Please remove the "advisory" keyword if it needs to be changed. It also helps when obsolete advisories are tagged as "obsolete" Keywords:
(none) =>
advisory MGA9-64 Plasma Wayland on HP Pavillion No installation issues. Ref bug 28943 for testing, but putty seems to react differently $ putty -l prutser <desktopPC> PuTTY: unable to load font "server:fixed" Googling learned me: $ env GDK_BACKEND=x11 putty -X -l prutser <desktopPC> libuim: [fatal] dynlib: /usr/lib64/uim/plugin/libuim-sqlite3.so: undefined symbol: uim_scm_c_int: Load failed. Session on <desktopPC> opens at CLI and that works OK, but I find no way of opening an X-session in this way. Note: <desktopPC> runs M9 Plasma X11 If someone can get X-conncetionn running, I'll agree on the OK. CC:
(none) =>
herman.viaene MGA9-64 Plasma No installation issues. I was able to connect via SSH to server, worked as expected. Set up profile - that worked I don't have anything I can try connecting as an X-Session at the moment, so this will have to wait on someone else or when I get some time. But, it works for me. CC:
(none) =>
brtians1 MGA9-64 Plasma on server installed and started sshd, open ssh port, installed xclock # urpmi xclock # urpmi sshd # systemctl start sshd # systemctl status sshd through putty I am able to connect to ssh server $ clock on ssh session pops up the xclock app Working as designed. Whiteboard:
(none) =>
MGA9-64-OK Validating. Keywords:
(none) =>
validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0003.html Resolution:
(none) =>
FIXED
Nicolas Salguero
2024-01-19 16:12:02 CET
Blocks:
(none) =>
32748
Nicolas Salguero
2024-01-19 16:16:44 CET
Blocks:
32748 =>
(none) |