Vulnerability CVE-2023-48795: Information

Description

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.

Severity: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Published: Dec. 18, 2023
Modified: Dec. 2, 2024
Error type identifier: CWE-354

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
cri-o1.27sisyphus1.27.6-alt11.27.8-alt1ALT-PU-2024-8173-4348675Fixed
cri-o1.27sisyphus_riscv641.27.6-alt11.27.8-alt1ALT-PU-2024-8511-1-Fixed
cri-o1.27sisyphus_loongarch641.27.6-alt11.27.8-alt1ALT-PU-2024-8530-1-Fixed
cri-o1.27p101.27.6-alt11.27.8-alt1ALT-PU-2024-8542-2349874Fixed
cri-o1.27c10f21.27.6-alt11.27.8-alt1ALT-PU-2024-8602-2350021Fixed
cri-o1.27p111.27.6-alt11.27.8-alt1ALT-PU-2024-8463-2349631Fixed
cri-o1.28sisyphus1.28.6-alt11.28.11-alt1ALT-PU-2024-8175-5348675Fixed
cri-o1.28sisyphus_riscv641.28.6-alt11.28.11-alt1ALT-PU-2024-8513-1-Fixed
cri-o1.28sisyphus_loongarch641.28.6-alt11.28.11-alt1ALT-PU-2024-8532-1-Fixed
cri-o1.28p101.28.6-alt11.28.10-alt1ALT-PU-2024-8544-2349874Fixed
cri-o1.28c10f21.28.6-alt11.28.10-alt1ALT-PU-2024-8605-2350021Fixed
cri-o1.28p111.28.6-alt11.28.10-alt1ALT-PU-2024-8461-2349631Fixed
dropbearsisyphus2022.83-alt22025.87-alt1ALT-PU-2024-2108-2340391Fixed
dropbearsisyphus_e2k2022.83-alt22024.86-alt1ALT-PU-2024-4421-1-Fixed
dropbearsisyphus_loongarch642022.83-alt22025.87-alt1ALT-PU-2024-2144-1-Fixed
dropbearp102022.83-alt22022.83-alt2ALT-PU-2024-4252-2343137Fixed
dropbearp10_e2k2022.83-alt22022.83-alt2ALT-PU-2024-4514-1-Fixed
dropbearc10f22024.85-alt12024.85-alt1ALT-PU-2024-7175-3345878Fixed
dropbearp112022.83-alt22024.86-alt1ALT-PU-2024-2108-2340391Fixed
erlangsisyphus26.2.5.3-alt126.2.5.3-alt2ALT-PU-2024-12987-3357883Fixed
erlangsisyphus_loongarch6426.2.5.3-alt126.2.5.3-alt2ALT-PU-2024-13247-1-Fixed
erlangp1026.2.5.3-alt126.2.5.3-alt1ALT-PU-2024-15421-2362342Fixed
erlangc10f226.2.5.3-alt126.2.5.3-alt1ALT-PU-2024-13219-2358196Fixed
erlangp1126.2.5.3-alt126.2.5.3-alt1ALT-PU-2024-13209-3358194Fixed
flannelc10f20.25.1-alt20.25.7-alt1ALT-PU-2024-8180-4348644Fixed
libsshsisyphus0.10.6-alt10.11.1-alt1ALT-PU-2024-1249-1338050Fixed
libsshsisyphus_e2k0.10.6-alt10.11.1-alt1ALT-PU-2024-1279-1-Fixed
libsshsisyphus_riscv640.10.6-alt10.11.1-alt1ALT-PU-2024-2714-1-Fixed
libsshsisyphus_loongarch640.10.6-alt10.11.1-alt1ALT-PU-2024-1440-1-Fixed
libsshp100.10.6-alt10.10.6-alt1ALT-PU-2024-1251-2338051Fixed
libsshp10_e2k0.10.6-alt10.10.6-alt1ALT-PU-2024-1381-1-Fixed
libsshc10f20.10.6-alt10.10.6-alt1ALT-PU-2024-1250-2338361Fixed
libsshc9f20.10.6-alt10.10.6-alt1ALT-PU-2024-1622-4339475Fixed
libsshp110.10.6-alt10.11.1-alt1ALT-PU-2024-1249-1338050Fixed
libssh2sisyphus1.11.0-alt21.11.0-alt2ALT-PU-2024-1561-1339356Fixed
libssh2sisyphus_e2k1.11.0-alt21.11.0-alt2ALT-PU-2024-1699-1-Fixed
libssh2sisyphus_riscv641.11.0-alt21.11.0-alt2ALT-PU-2024-3231-1-Fixed
libssh2sisyphus_loongarch641.11.0-alt21.11.0-alt2ALT-PU-2024-1601-1-Fixed
libssh2p101.11.0-alt21.11.0-alt2ALT-PU-2024-1563-2339351Fixed
libssh2p10_e2k1.11.0-alt21.11.0-alt2ALT-PU-2024-1964-1-Fixed
libssh2c10f21.11.0-alt21.11.0-alt2ALT-PU-2024-1562-2339357Fixed
libssh2c9f21.11.0-alt21.11.0-alt2ALT-PU-2024-4039-2342773Fixed
libssh2p111.11.0-alt21.11.0-alt2ALT-PU-2024-1561-1339356Fixed
openquantumsafe-opensshsisyphus8.9p1.202310-alt28.9p1.202310-alt4ALT-PU-2024-1046-5337714Fixed
openquantumsafe-opensshc10f28.9p1.202310-alt38.9p1.202310-alt3ALT-PU-2024-17393-3365537Fixed
openquantumsafe-opensshp118.9p1.202310-alt28.9p1.202310-alt4ALT-PU-2024-1046-5337714Fixed
opensshsisyphus9.5p1-alt29.6p1-alt3ALT-PU-2024-1247-2338314Fixed
opensshsisyphus_e2k9.5p1-alt29.6p1-alt2ALT-PU-2024-8876-1-Fixed
opensshsisyphus_riscv649.5p1-alt29.6p1-alt3ALT-PU-2024-2876-1-Fixed
opensshsisyphus_loongarch649.5p1-alt29.6p1-alt3ALT-PU-2024-1471-1-Fixed
opensshp107.9p1-alt4.p10.47.9p1-alt4.p10.7ALT-PU-2024-1190-3338315Fixed
opensshp10_e2k7.9p1-alt4.p10.47.9p1-alt4.p10.7ALT-PU-2024-1468-1-Fixed
opensshp97.9p1-alt4.p10.67.9p1-alt4.p10.7ALT-PU-2024-12012-3356748Fixed
opensshc10f27.9p1-alt4.p10.47.9p1-alt4.p10.7ALT-PU-2024-1333-3338780Fixed
opensshc9f27.9p1-alt4.p10.47.9p1-alt4.p10.7ALT-PU-2024-1569-3339369Fixed
opensshp119.5p1-alt29.6p1-alt3ALT-PU-2024-1247-2338314Fixed
openssh-gostcryptosisyphus9.6p1-alt1.gost9.6p1-alt3.gostALT-PU-2024-7269-2344956Fixed
openssh-gostcryptop107.9p1-alt4.gost.p10.17.9p1-alt4.gost.p10.4ALT-PU-2024-3921-4342647Fixed
openssh-gostcryptop97.9p1-alt4.gost.p10.37.9p1-alt4.gost.p10.4ALT-PU-2024-12010-3356748Fixed
openssh-gostcryptoc10f27.9p1-alt4.gost.p10.17.9p1-alt4.gost.p10.4ALT-PU-2024-4182-3343010Fixed
openssh-gostcryptoc9f27.9p1-alt4.gost.p10.17.9p1-alt4.gost.p10.4ALT-PU-2024-4077-3342832Fixed
openssh-gostcryptop119.6p1-alt2.gost9.6p1-alt3.gostALT-PU-2024-9513-3351933Fixed
podmansisyphus4.8.3-alt15.4.0-alt1ALT-PU-2024-1096-1337978Fixed
podmansisyphus_riscv644.8.3-alt15.4.0-alt1ALT-PU-2024-1101-1-Fixed
podmansisyphus_loongarch644.8.3-alt15.4.0-alt1ALT-PU-2024-1104-1-Fixed
podmanp114.8.3-alt15.4.0-alt1ALT-PU-2024-1096-1337978Fixed
proftpdsisyphus1.3.9-alt0.1.rc21.3.9-alt0.4.rc3ALT-PU-2024-11072-2330474Fixed
proftpdsisyphus_riscv641.3.9-alt0.1.rc21.3.9-alt0.4.rc3ALT-PU-2024-11097-1-Fixed
proftpdsisyphus_loongarch641.3.9-alt0.1.rc21.3.9-alt0.4.rc3ALT-PU-2024-11104-1-Fixed
puttysisyphus0.81-alt10.83-alt1ALT-PU-2024-6830-1345428Fixed
puttysisyphus_e2k0.81-alt10.81-alt2ALT-PU-2024-6884-1-Fixed
puttysisyphus_loongarch640.81-alt10.83-alt1ALT-PU-2024-6895-1-Fixed
puttyp100.81-alt20.81-alt2ALT-PU-2024-9848-2351368Fixed
puttyp10_e2k0.81-alt20.81-alt2ALT-PU-2024-9995-1-Fixed
puttyc10f20.81-alt20.81-alt2ALT-PU-2024-9398-2351553Fixed
puttyc9f20.81-alt20.81-alt2ALT-PU-2024-9396-2351555Fixed
puttyp110.81-alt10.81-alt2ALT-PU-2024-6830-1345428Fixed
python3-module-asyncsshsisyphus2.14.2-alt12.20.0-alt1ALT-PU-2024-8723-1350401Fixed
python3-module-asyncsshsisyphus_e2k2.19.0-alt12.19.0-alt1ALT-PU-2025-4257-1-Fixed
python3-module-asyncsshsisyphus_riscv642.14.2-alt12.20.0-alt1ALT-PU-2024-8745-1-Fixed
python3-module-asyncsshsisyphus_loongarch642.14.2-alt12.20.0-alt1ALT-PU-2024-8754-1-Fixed
python3-module-asyncsshp112.19.0-alt12.19.0-alt1ALT-PU-2025-2804-5370642Fixed
python3-module-paramikosisyphus3.4.0-alt13.5.1-alt1ALT-PU-2024-1940-2339791Fixed
python3-module-paramikosisyphus_e2k3.4.0-alt13.4.0-alt1ALT-PU-2024-2375-1-Fixed
python3-module-paramikosisyphus_riscv643.4.0-alt13.5.1-alt1ALT-PU-2024-3369-1-Fixed
python3-module-paramikosisyphus_loongarch643.4.0-alt13.5.1-alt1ALT-PU-2024-2089-1-Fixed
python3-module-paramikop113.4.0-alt13.4.0-alt1ALT-PU-2024-1940-2339791Fixed
resticprofilesisyphus0.25.0-alt10.29.1-alt1ALT-PU-2024-2064-2340331Fixed
resticprofilesisyphus_loongarch640.25.0-alt10.29.1-alt1ALT-PU-2024-2140-1-Fixed
resticprofilec10f20.25.0-alt10.26.0-alt1.1ALT-PU-2024-2064-2340331Fixed
resticprofilep110.25.0-alt10.26.0-alt1.1ALT-PU-2024-2064-2340331Fixed
tinysshsisyphus20240101-alt120250201-alt1ALT-PU-2024-1001-2337569Fixed
tinysshsisyphus_e2k20240101-alt120240101-alt1ALT-PU-2024-1054-1-Fixed
tinysshsisyphus_loongarch6420240101-alt120250201-alt1ALT-PU-2024-1023-1-Fixed
tinysshp1120240101-alt120240101-alt1ALT-PU-2024-1001-2337569Fixed
vaultsisyphus1.13.12-alt31.13.12-alt6ALT-PU-2024-9089-3350936Fixed
vaultsisyphus_riscv641.13.12-alt41.13.12-alt6ALT-PU-2024-9105-1-Fixed
vaultsisyphus_loongarch641.13.12-alt41.13.12-alt6ALT-PU-2024-9117-1-Fixed
vaultp101.13.12-alt41.13.12-alt6ALT-PU-2024-9897-3351699Fixed
vaultc10f21.13.12-alt41.13.12-alt6ALT-PU-2024-9901-3352701Fixed
vaultc9f21.13.12-alt51.13.12-alt6ALT-PU-2024-12410-2356974Fixed
vaultp111.13.12-alt41.13.12-alt6ALT-PU-2024-9408-3351672Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html
  • Third Party Advisory
  • VDB Entry
http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html
  • Third Party Advisory
  • VDB Entry
20240313 APPLE-SA-03-07-2024-2 macOS Sonoma 14.4
  • Mailing List
  • Third Party Advisory
20240313 APPLE-SA-03-07-2024-2 macOS Sonoma 14.4
  • Mailing List
  • Third Party Advisory
[oss-security] 20231218 CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)
  • Mailing List
[oss-security] 20231218 CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)
  • Mailing List
[oss-security] 20231219 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)
  • Mailing List
[oss-security] 20231219 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)
  • Mailing List
[oss-security] 20231220 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)
  • Mailing List
  • Mitigation
[oss-security] 20231220 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)
  • Mailing List
  • Mitigation
[oss-security] 20240306 Multiple vulnerabilities in Jenkins plugins
  • Mailing List
[oss-security] 20240306 Multiple vulnerabilities in Jenkins plugins
  • Mailing List
[oss-security] 20240417 Terrapin vulnerability in Jenkins CLI client
  • Mailing List
[oss-security] 20240417 Terrapin vulnerability in Jenkins CLI client
  • Mailing List
https://access.redhat.com/security/cve/cve-2023-48795
  • Third Party Advisory
https://access.redhat.com/security/cve/cve-2023-48795
  • Third Party Advisory
https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/
  • Press/Media Coverage
https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/
  • Press/Media Coverage
https://bugs.gentoo.org/920280
  • Issue Tracking
https://bugs.gentoo.org/920280
  • Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2254210
  • Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2254210
  • Issue Tracking
https://bugzilla.suse.com/show_bug.cgi?id=1217950
  • Issue Tracking
https://bugzilla.suse.com/show_bug.cgi?id=1217950
  • Issue Tracking
https://crates.io/crates/thrussh/versions
  • Release Notes
https://crates.io/crates/thrussh/versions
  • Release Notes
https://filezilla-project.org/versions.php
  • Release Notes
https://filezilla-project.org/versions.php
  • Release Notes
https://forum.netgate.com/topic/184941/terrapin-ssh-attack
  • Issue Tracking
https://forum.netgate.com/topic/184941/terrapin-ssh-attack
  • Issue Tracking
https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6
  • Patch
https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6
  • Patch
https://github.com/advisories/GHSA-45x7-px36-x8w8
  • Third Party Advisory
https://github.com/advisories/GHSA-45x7-px36-x8w8
  • Third Party Advisory
https://github.com/apache/mina-sshd/issues/445
  • Issue Tracking
https://github.com/apache/mina-sshd/issues/445
  • Issue Tracking
https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab
  • Patch
https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab
  • Patch
https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22
  • Third Party Advisory
https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22
  • Third Party Advisory
https://github.com/cyd01/KiTTY/issues/520
  • Issue Tracking
https://github.com/cyd01/KiTTY/issues/520
  • Issue Tracking
https://github.com/drakkan/sftpgo/releases/tag/v2.5.6
  • Release Notes
https://github.com/drakkan/sftpgo/releases/tag/v2.5.6
  • Release Notes
https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42
  • Patch
https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42
  • Patch
https://github.com/erlang/otp/releases/tag/OTP-26.2.1
  • Release Notes
https://github.com/erlang/otp/releases/tag/OTP-26.2.1
  • Release Notes
https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d
  • Patch
https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d
  • Patch
https://github.com/hierynomus/sshj/issues/916
  • Issue Tracking
https://github.com/hierynomus/sshj/issues/916
  • Issue Tracking
https://github.com/janmojzis/tinyssh/issues/81
  • Issue Tracking
https://github.com/janmojzis/tinyssh/issues/81
  • Issue Tracking
https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5
  • Patch
https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5
  • Patch
https://github.com/libssh2/libssh2/pull/1291
  • Mitigation
https://github.com/libssh2/libssh2/pull/1291
  • Mitigation
https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25
  • Patch
https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25
  • Patch
https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3
  • Patch
https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3
  • Patch
https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15
  • Product
https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15
  • Product
https://github.com/mwiede/jsch/issues/457
  • Issue Tracking
https://github.com/mwiede/jsch/issues/457
  • Issue Tracking
https://github.com/mwiede/jsch/pull/461
  • Release Notes
https://github.com/mwiede/jsch/pull/461
  • Release Notes
https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16
  • Patch
https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16
  • Patch
https://github.com/NixOS/nixpkgs/pull/275249
  • Release Notes
https://github.com/NixOS/nixpkgs/pull/275249
  • Release Notes
https://github.com/openssh/openssh-portable/commits/master
  • Patch
https://github.com/openssh/openssh-portable/commits/master
  • Patch
https://github.com/paramiko/paramiko/issues/2337
  • Issue Tracking
https://github.com/paramiko/paramiko/issues/2337
  • Issue Tracking
https://github.com/PowerShell/Win32-OpenSSH/issues/2189
  • Issue Tracking
https://github.com/PowerShell/Win32-OpenSSH/issues/2189
  • Issue Tracking
https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta
  • Release Notes
https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta
  • Release Notes
https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES
  • Release Notes
https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES
  • Release Notes
https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES
  • Release Notes
https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES
  • Release Notes
https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
  • Release Notes
https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
  • Release Notes
https://github.com/proftpd/proftpd/issues/456
  • Issue Tracking
https://github.com/proftpd/proftpd/issues/456
  • Issue Tracking
https://github.com/rapier1/hpn-ssh/releases
  • Release Notes
https://github.com/rapier1/hpn-ssh/releases
  • Release Notes
https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst
  • Release Notes
https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst
  • Release Notes
https://github.com/ronf/asyncssh/tags
  • Release Notes
https://github.com/ronf/asyncssh/tags
  • Release Notes
https://github.com/ssh-mitm/ssh-mitm/issues/165
  • Issue Tracking
https://github.com/ssh-mitm/ssh-mitm/issues/165
  • Issue Tracking
https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0
  • Patch
https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0
  • Patch
https://github.com/TeraTermProject/teraterm/releases/tag/v5.1
  • Release Notes
https://github.com/TeraTermProject/teraterm/releases/tag/v5.1
  • Release Notes
https://github.com/warp-tech/russh/releases/tag/v0.40.2
  • Release Notes
https://github.com/warp-tech/russh/releases/tag/v0.40.2
  • Release Notes
https://gitlab.com/libssh/libssh-mirror/-/tags
  • Release Notes
https://gitlab.com/libssh/libssh-mirror/-/tags
  • Release Notes
https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ
  • Mailing List
https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ
  • Mailing List
https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg
  • Mailing List
https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg
  • Mailing List
https://help.panic.com/releasenotes/transmit5/
  • Release Notes
https://help.panic.com/releasenotes/transmit5/
  • Release Notes
https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/
  • Press/Media Coverage
https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/
  • Press/Media Coverage
[debian-lts-announce] 20231226 [SECURITY] [DLA 3694-1] openssh security update
  • Mailing List
[debian-lts-announce] 20231226 [SECURITY] [DLA 3694-1] openssh security update
  • Mailing List
[debian-lts-announce] 20240125 [SECURITY] [DLA 3718-1] php-phpseclib security update
  • Mailing List
  • Third Party Advisory
[debian-lts-announce] 20240125 [SECURITY] [DLA 3718-1] php-phpseclib security update
  • Mailing List
  • Third Party Advisory
[debian-lts-announce] 20240125 [SECURITY] [DLA 3719-1] phpseclib security update
  • Mailing List
  • Third Party Advisory
[debian-lts-announce] 20240125 [SECURITY] [DLA 3719-1] phpseclib security update
  • Mailing List
  • Third Party Advisory
[debian-lts-announce] 20240425 [SECURITY] [DLA 3794-1] putty security update
  • Mailing List
  • Third Party Advisory
[debian-lts-announce] 20240425 [SECURITY] [DLA 3794-1] putty security update
  • Mailing List
  • Third Party Advisory
FEDORA-2024-39a8c72ea9
  • Mailing List
  • Third Party Advisory
FEDORA-2024-39a8c72ea9
  • Mailing List
  • Third Party Advisory
FEDORA-2024-3bb23c77f3
  • Mailing List
  • Third Party Advisory
FEDORA-2024-3bb23c77f3
  • Mailing List
  • Third Party Advisory
FEDORA-2024-3fd1bc9276
  • Mailing List
  • Third Party Advisory
FEDORA-2024-3fd1bc9276
  • Mailing List
  • Third Party Advisory
FEDORA-2023-20feb865d8
  • Mailing List
  • Third Party Advisory
FEDORA-2023-20feb865d8
  • Mailing List
  • Third Party Advisory
FEDORA-2024-06ebb70bdd
  • Mailing List
  • Third Party Advisory
FEDORA-2024-06ebb70bdd
  • Mailing List
  • Third Party Advisory
FEDORA-2023-e77300e4b5
  • Mailing List
  • Third Party Advisory
FEDORA-2023-e77300e4b5
  • Mailing List
  • Third Party Advisory
FEDORA-2024-71c2c6526c
  • Mailing List
  • Third Party Advisory
FEDORA-2024-71c2c6526c
  • Mailing List
  • Third Party Advisory
FEDORA-2024-d946b9ad25
  • Mailing List
  • Third Party Advisory
FEDORA-2024-d946b9ad25
  • Mailing List
  • Third Party Advisory
FEDORA-2024-ae653fb07b
  • Mailing List
  • Third Party Advisory
FEDORA-2024-ae653fb07b
  • Mailing List
  • Third Party Advisory
FEDORA-2023-cb8c606fbb
  • Mailing List
  • Third Party Advisory
FEDORA-2023-cb8c606fbb
  • Mailing List
  • Third Party Advisory
FEDORA-2024-7b08207cdb
  • Mailing List
  • Third Party Advisory
FEDORA-2024-7b08207cdb
  • Mailing List
  • Third Party Advisory
FEDORA-2024-2705241461
  • Mailing List
  • Third Party Advisory
FEDORA-2024-2705241461
  • Mailing List
  • Third Party Advisory
FEDORA-2024-fb32950d11
  • Mailing List
  • Third Party Advisory
FEDORA-2024-fb32950d11
  • Mailing List
  • Third Party Advisory
FEDORA-2023-153404713b
  • Mailing List
  • Third Party Advisory
FEDORA-2023-153404713b
  • Mailing List
  • Third Party Advisory
FEDORA-2024-a53b24023d
  • Mailing List
  • Third Party Advisory
FEDORA-2024-a53b24023d
  • Mailing List
  • Third Party Advisory
FEDORA-2023-55800423a8
  • Mailing List
  • Third Party Advisory
FEDORA-2023-55800423a8
  • Mailing List
  • Third Party Advisory
FEDORA-2023-0733306be9
  • Vendor Advisory
FEDORA-2023-0733306be9
  • Vendor Advisory
FEDORA-2023-b87ec6cf47
  • Mailing List
  • Third Party Advisory
FEDORA-2023-b87ec6cf47
  • Mailing List
  • Third Party Advisory
https://matt.ucc.asn.au/dropbear/CHANGES
  • Release Notes
https://matt.ucc.asn.au/dropbear/CHANGES
  • Release Notes
https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC
  • Patch
https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC
  • Patch
https://news.ycombinator.com/item?id=38684904
  • Issue Tracking
https://news.ycombinator.com/item?id=38684904
  • Issue Tracking
https://news.ycombinator.com/item?id=38685286
  • Issue Tracking
https://news.ycombinator.com/item?id=38685286
  • Issue Tracking
https://news.ycombinator.com/item?id=38732005
  • Issue Tracking
https://news.ycombinator.com/item?id=38732005
  • Issue Tracking
https://nova.app/releases/#v11.8
  • Release Notes
https://nova.app/releases/#v11.8
  • Release Notes
https://oryx-embedded.com/download/#changelog
  • Release Notes
https://oryx-embedded.com/download/#changelog
  • Release Notes
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002
  • Third Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002
  • Third Party Advisory
https://roumenpetrov.info/secsh/#news20231220
  • Release Notes
https://roumenpetrov.info/secsh/#news20231220
  • Release Notes
GLSA-202312-16
  • Third Party Advisory
GLSA-202312-16
  • Third Party Advisory
GLSA-202312-17
  • Third Party Advisory
GLSA-202312-17
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20240105-0004/
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20240105-0004/
  • Third Party Advisory
https://security-tracker.debian.org/tracker/CVE-2023-48795
  • Vendor Advisory
https://security-tracker.debian.org/tracker/CVE-2023-48795
  • Vendor Advisory
https://security-tracker.debian.org/tracker/source-package/libssh2
  • Vendor Advisory
https://security-tracker.debian.org/tracker/source-package/libssh2
  • Vendor Advisory
https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg
  • Vendor Advisory
https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg
  • Vendor Advisory
https://security-tracker.debian.org/tracker/source-package/trilead-ssh2
  • Issue Tracking
https://security-tracker.debian.org/tracker/source-package/trilead-ssh2
  • Issue Tracking
https://support.apple.com/kb/HT214084
  • Third Party Advisory
https://support.apple.com/kb/HT214084
  • Third Party Advisory
https://thorntech.com/cve-2023-48795-and-sftp-gateway/
  • Third Party Advisory
https://thorntech.com/cve-2023-48795-and-sftp-gateway/
  • Third Party Advisory
https://twitter.com/TrueSkrillor/status/1736774389725565005
  • Press/Media Coverage
https://twitter.com/TrueSkrillor/status/1736774389725565005
  • Press/Media Coverage
https://ubuntu.com/security/CVE-2023-48795
  • Vendor Advisory
https://ubuntu.com/security/CVE-2023-48795
  • Vendor Advisory
https://winscp.net/eng/docs/history#6.2.2
  • Release Notes
https://winscp.net/eng/docs/history#6.2.2
  • Release Notes
https://www.bitvise.com/ssh-client-version-history#933
  • Release Notes
https://www.bitvise.com/ssh-client-version-history#933
  • Release Notes
https://www.bitvise.com/ssh-server-version-history
  • Release Notes
https://www.bitvise.com/ssh-server-version-history
  • Release Notes
https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
  • Release Notes
https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
  • Release Notes
https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update
  • Release Notes
https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update
  • Release Notes
DSA-5586
  • Issue Tracking
DSA-5586
  • Issue Tracking
DSA-5588
  • Issue Tracking
DSA-5588
  • Issue Tracking
https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc
  • Release Notes
https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc
  • Release Notes
https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508
  • Vendor Advisory
https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508
  • Vendor Advisory
https://www.netsarang.com/en/xshell-update-history/
  • Release Notes
https://www.netsarang.com/en/xshell-update-history/
  • Release Notes
https://www.openssh.com/openbsd.html
  • Release Notes
https://www.openssh.com/openbsd.html
  • Release Notes
https://www.openssh.com/txt/release-9.6
  • Release Notes
https://www.openssh.com/txt/release-9.6
  • Release Notes
https://www.openwall.com/lists/oss-security/2023/12/18/2
  • Mailing List
https://www.openwall.com/lists/oss-security/2023/12/18/2
  • Mailing List
https://www.openwall.com/lists/oss-security/2023/12/20/3
  • Mailing List
  • Mitigation
https://www.openwall.com/lists/oss-security/2023/12/20/3
  • Mailing List
  • Mitigation
https://www.paramiko.org/changelog.html
  • Release Notes
https://www.paramiko.org/changelog.html
  • Release Notes
https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/
  • Issue Tracking
https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/
  • Issue Tracking
https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/
  • Press/Media Coverage
https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/
  • Press/Media Coverage
https://www.terrapin-attack.com
  • Exploit
https://www.terrapin-attack.com
  • Exploit
https://www.theregister.com/2023/12/20/terrapin_attack_ssh
  • Press/Media Coverage
https://www.theregister.com/2023/12/20/terrapin_attack_ssh
  • Press/Media Coverage
https://www.vandyke.com/products/securecrt/history.txt
  • Release Notes
https://www.vandyke.com/products/securecrt/history.txt
  • Release Notes
    1. Configuration 1

      cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
      End excluding
      9.6

      Configuration 2

      cpe:2.3:a:putty:putty:*:*:*:*:*:*:*:*
      End excluding
      0.80

      Configuration 3

      cpe:2.3:a:filezilla-project:filezilla_client:*:*:*:*:*:*:*:*
      End excluding
      3.66.4

      Configuration 4

      cpe:2.3:a:microsoft:powershell:*:*:*:*:*:*:*:*
      End including
      11.1.0

      Configuration 5

      Running on/with:
      cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

      cpe:2.3:a:panic:transmit_5:*:*:*:*:*:*:*:*

      Configuration 6

      Running on/with:
      cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

      cpe:2.3:a:panic:nova:*:*:*:*:*:*:*:*

      Configuration 7

      cpe:2.3:a:roumenpetrov:pkixssh:*:*:*:*:*:*:*:*
      End excluding
      14.4

      Configuration 8

      cpe:2.3:a:winscp:winscp:*:*:*:*:*:*:*:*
      End excluding
      6.2.2

      Configuration 9

      cpe:2.3:a:bitvise:ssh_client:*:*:*:*:*:*:*:*
      End excluding
      9.33

      Configuration 10

      cpe:2.3:a:bitvise:ssh_server:*:*:*:*:*:*:*:*
      End excluding
      9.32

      Configuration 11

      cpe:2.3:o:lancom-systems:lcos:*:*:*:*:*:*:*:*
      End including
      3.66.4

      Configuration 12

      cpe:2.3:o:lancom-systems:lcos_fx:-:*:*:*:*:*:*:*

      Configuration 13

      cpe:2.3:o:lancom-systems:lcos_lx:-:*:*:*:*:*:*:*

      Configuration 14

      cpe:2.3:o:lancom-systems:lcos_sx:5.20:*:*:*:*:*:*:*

      cpe:2.3:o:lancom-systems:lcos_sx:4.20:*:*:*:*:*:*:*

      Configuration 15

      cpe:2.3:o:lancom-systems:lanconfig:-:*:*:*:*:*:*:*

      Configuration 16

      cpe:2.3:a:vandyke:securecrt:*:*:*:*:*:*:*:*
      End excluding
      9.4.3

      Configuration 17

      cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
      End excluding
      0.10.6

      Configuration 18

      cpe:2.3:a:net-ssh:net-ssh:7.2.0:*:*:*:*:ruby:*:*

      Configuration 19

      cpe:2.3:a:ssh2_project:ssh2:*:*:*:*:*:node.js:*:*
      End including
      1.11.0

      Configuration 20

      cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*
      End including
      1.3.8b

      Configuration 21

      cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
      End including
      12.4

      Configuration 22

      cpe:2.3:a:crates:thrussh:*:*:*:*:*:*:*:*
      End excluding
      0.35.1

      Configuration 23

      cpe:2.3:a:tera_term_project:tera_term:*:*:*:*:*:*:*:*
      End including
      5.1

      Configuration 24

      cpe:2.3:a:oryx-embedded:cyclone_ssh:*:*:*:*:*:*:*:*
      End excluding
      2.3.4

      Configuration 25

      cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*
      End including
      10.6.0

      Configuration 26

      cpe:2.3:a:netsarang:xshell_7:*:*:*:*:*:*:*:*
      End excluding
      build__0144

      Configuration 27

      cpe:2.3:a:paramiko:paramiko:*:*:*:*:*:*:*:*
      End excluding
      3.4.0

      Configuration 28

      cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*

      Configuration 29

      cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:openstack_platform:17.1:*:*:*:*:*:*:*

      Configuration 30

      cpe:2.3:a:redhat:ceph_storage:6.0:*:*:*:*:*:*:*

      Configuration 31

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

      Configuration 32

      cpe:2.3:a:redhat:openshift_serverless:-:*:*:*:*:*:*:*

      Configuration 33

      cpe:2.3:a:redhat:openshift_gitops:-:*:*:*:*:*:*:*

      Configuration 34

      cpe:2.3:a:redhat:openshift_pipelines:-:*:*:*:*:*:*:*

      Configuration 35

      cpe:2.3:a:redhat:openshift_developer_tools_and_services:-:*:*:*:*:*:*:*

      Configuration 36

      cpe:2.3:a:redhat:openshift_data_foundation:4.0:*:*:*:*:*:*:*

      Configuration 37

      cpe:2.3:a:redhat:openshift_api_for_data_protection:-:*:*:*:*:*:*:*

      Configuration 38

      cpe:2.3:a:redhat:openshift_virtualization:4:*:*:*:*:*:*:*

      Configuration 39

      cpe:2.3:a:redhat:storage:3.0:*:*:*:*:*:*:*

      Configuration 40

      cpe:2.3:a:redhat:discovery:-:*:*:*:*:*:*:*

      Configuration 41

      cpe:2.3:a:redhat:openshift_dev_spaces:-:*:*:*:*:*:*:*

      Configuration 42

      cpe:2.3:a:redhat:cert-manager_operator_for_red_hat_openshift:-:*:*:*:*:*:*:*

      Configuration 43

      cpe:2.3:a:redhat:keycloak:-:*:*:*:*:*:*:*

      Configuration 44

      cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0:*:*:*:*:*:*:*

      Configuration 45

      cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*

      Configuration 46

      cpe:2.3:a:redhat:advanced_cluster_security:4.0:*:*:*:*:*:*:*

      cpe:2.3:a:redhat:advanced_cluster_security:3.0:*:*:*:*:*:*:*

      Configuration 47

      cpe:2.3:a:golang:crypto:*:*:*:*:*:*:*:*
      End excluding
      0.17.0

      Configuration 48

      cpe:2.3:a:russh_project:russh:*:*:*:*:*:rust:*:*
      End excluding
      0.40.2

      Configuration 49

      cpe:2.3:a:sftpgo_project:sftpgo:*:*:*:*:*:*:*:*
      End excluding
      2.5.6

      Configuration 50

      cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
      End excluding
      26.2.1

      Configuration 51

      cpe:2.3:a:matez:jsch:*:*:*:*:*:*:*:*
      End excluding
      0.2.15

      Configuration 52

      cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:*
      End excluding
      1.11.1

      Configuration 53

      cpe:2.3:a:asyncssh_project:asyncssh:*:*:*:*:*:*:*:*
      End excluding
      2.14.2

      Configuration 54

      cpe:2.3:a:dropbear_ssh_project:dropbear_ssh:*:*:*:*:*:*:*:*
      End excluding
      2022.83

      Configuration 55

      cpe:2.3:a:jadaptive:maverick_synergy_java_ssh_api:*:*:*:*:*:*:*:*
      End excluding
      3.1.0-snapshot

      Configuration 56

      cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*
      End excluding
      5.11

      Configuration 57

      cpe:2.3:o:thorntech:sftp_gateway_firmware:*:*:*:*:*:*:*:*
      End excluding
      3.4.6

      Configuration 58

      cpe:2.3:a:netgate:pfsense_plus:*:*:*:*:*:*:*:*
      End including
      23.09.1

      Configuration 59

      cpe:2.3:a:netgate:pfsense_ce:*:*:*:*:*:*:*:*
      End including
      2.7.2

      Configuration 60

      cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*
      End excluding
      10.6.0

      Configuration 61

      cpe:2.3:a:connectbot:sshlib:*:*:*:*:*:*:*:*
      End excluding
      2.2.22

      Configuration 62

      cpe:2.3:a:apache:sshd:*:*:*:*:*:*:*:*
      End including
      2.11.0

      Configuration 63

      cpe:2.3:a:apache:sshj:*:*:*:*:*:*:*:*
      End including
      0.37.0

      Configuration 64

      cpe:2.3:a:tinyssh:tinyssh:*:*:*:*:*:*:*:*
      End including
      20230101

      Configuration 65

      cpe:2.3:a:trilead:ssh2:6401:*:*:*:*:*:*:*

      Configuration 66

      cpe:2.3:a:9bis:kitty:*:*:*:*:*:*:*:*
      End including
      0.76.1.13

      Configuration 67

      cpe:2.3:a:gentoo:security:-:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:debian:debian_linux:-:*:*:*:*:*:*:*

      Configuration 68

      cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

      Configuration 69

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      Configuration 70

      cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
      Start including
      14.0
      End excluding
      14.4