Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update: net-misc/openssh (Terrapin) #1301

Closed
tormath1 opened this issue Dec 19, 2023 · 0 comments · Fixed by flatcar/scripts#1551
Closed

update: net-misc/openssh (Terrapin) #1301

tormath1 opened this issue Dec 19, 2023 · 0 comments · Fixed by flatcar/scripts#1551
Labels
advisory security advisory cvss/MEDIUM >= 4 && < 7 assessed CVSS security security concerns

Comments

@tormath1
Copy link
Contributor

tormath1 commented Dec 19, 2023

Name: net-misc/openssh
CVEs: CVE-2023-48795
CVSSs: 5.9
Action Needed: upgrade to openssh >=9.6_p1

Summary: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack.

refmap.gentoo: https://bugs.gentoo.org/920292

@tormath1 tormath1 added security security concerns advisory security advisory labels Dec 19, 2023
@dongsupark dongsupark moved this from 📝 Needs Triage to 🪵Backlog in Flatcar tactical, release planning, and roadmap Dec 22, 2023
@dongsupark dongsupark added the cvss/MEDIUM >= 4 && < 7 assessed CVSS label Jan 5, 2024
@dongsupark dongsupark changed the title update: dev-libs/openssh (Terrapin) update: net-misc/openssh, net-libs/libssh (Terrapin) Jan 5, 2024
@dongsupark dongsupark changed the title update: net-misc/openssh, net-libs/libssh (Terrapin) update: net-misc/openssh (Terrapin) Jan 5, 2024
@krnowak krnowak moved this from 🪵Backlog to ⚒️ In Progress in Flatcar tactical, release planning, and roadmap Jan 5, 2024
@krnowak krnowak moved this from ⚒️ In Progress to 🪵Backlog in Flatcar tactical, release planning, and roadmap Jan 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
advisory security advisory cvss/MEDIUM >= 4 && < 7 assessed CVSS security security concerns
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants