| Summary: | CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack) - jsch | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Marja Van Waes <marja11> |
| Component: | Security | Assignee: | Nicolas Lécureuil <mageia> |
| Status: | RESOLVED INVALID | QA Contact: | Sec team <security> |
| Severity: | critical | ||
| Priority: | Normal | CC: | geiger.david68210, lewyssmith, marja11, nicolas.salguero, pkg-bugs, security, yvesbrungard |
| Version: | Cauldron | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA9TOO | ||
| Source RPM: | jsch-0.1.55-8.mga9 | CVE: | CVE-2023-48795 |
| Status comment: | |||
| Bug Depends on: | |||
| Bug Blocks: | 32641 | ||
|
Description
Marja Van Waes
2023-12-31 18:11:27 CET
Marja Van Waes
2023-12-31 18:13:28 CET
Whiteboard:
(none) =>
MGA9TOO
Marja Van Waes
2024-01-02 12:00:26 CET
CVE:
(none) =>
CVE-2023-48795
Nicolas Salguero
2024-01-19 16:12:02 CET
Blocks:
(none) =>
32748
Nicolas Salguero
2024-01-19 16:16:44 CET
Blocks:
32748 =>
(none) According to https://security-tracker.debian.org/tracker/CVE-2023-48795, our version is not affected because: - ChaCha20-Poly1305 support was introduced in 0.1.61; - *-EtM support was introduced in 0.1.58. Resolution:
(none) =>
INVALID |