https://seclists.org/oss-sec/2023/q4/297: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)
Published Dec 19, 2023
·Updated
Affected Software
10 affected components
AsyncSSH AsyncSSH
Dropbear Dropbear
Erlang Erlang ssh
Golang golang.org/x/crypto
libssh libssh>=0.9.8<=0.10.6
libssh2 libssh2
OpenSSH OpenSSH
Paramiko Paramiko
Putty PuTTY
russh russh
Frequently Asked Questions
1
What is the severity of CVE-2023-48795?
CVE-2023-48795 is classified as a critical vulnerability due to its potential to enable prefix truncation attacks in SSH.
2
How do I fix CVE-2023-48795?
To fix CVE-2023-48795, update your SSH implementation to the latest version that includes the mitigation for this vulnerability.
3
Which software is affected by CVE-2023-48795?
CVE-2023-48795 affects several SSH implementations including AsyncSSH, Dropbear, OpenSSH, libssh, and others.
4
Is there a known exploit for CVE-2023-48795?
Yes, there are reports detailing how the vulnerability can be exploited in real-world scenarios.