USN-6598-1: Paramiko vulnerability
Fabian Bäumer, Marcus Brinkmann, Jörg Schwenk discovered that the SSH protocol was vulnerable to a prefix truncation attack. If a remote attacker was able to intercept SSH communications, extension negotiation messages could be truncated, possibly leading to certain algorithms and features being downgraded. This issue is known as the Terrapin attack. This update adds protocol extensions to mitigate this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6598-1?
The severity of USN-6598-1 is critical due to the potential for a prefix truncation attack on SSH communications.
How do I fix USN-6598-1?
To fix USN-6598-1, upgrade the python3-paramiko package to the remedied version specific to your Ubuntu release.
What versions of Ubuntu are affected by USN-6598-1?
USN-6598-1 affects Ubuntu versions 20.04, 22.04, and 23.10.
What is the nature of the vulnerability described in USN-6598-1?
The vulnerability described in USN-6598-1 involves a prefix truncation attack that can intercept SSH communications.
Who discovered the vulnerability in USN-6598-1?
The vulnerability in USN-6598-1 was discovered by Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk.