https://seclists.org/oss-sec/2023/q4/300: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)
Published Dec 20, 2023
·Updated
Affected Software
4 affected components
AsyncSSH AsyncSSH
Dropbear Dropbear
Erlang Erlang ssh
go golang.org/x/crypto
Frequently Asked Questions
1
What is the severity of CVE-2023-48795?
CVE-2023-48795 is considered a serious vulnerability that allows for prefix truncation attacks in SSH, potentially enabling Man-in-the-Middle exploitation.
2
How do I fix CVE-2023-48795?
To fix CVE-2023-48795, implement OpenSSH's 'strict kex' mitigation during the SSH handshake process.
3
What software is affected by CVE-2023-48795?
CVE-2023-48795 affects multiple SSH implementations including AsyncSSH, Dropbear, Erlang ssh, and go golang.org/x/crypto.
4
What is the nature of the attack associated with CVE-2023-48795?
The attack associated with CVE-2023-48795 is a prefix truncation attack that targets the SSH protocol's handshake process.
5
When was CVE-2023-48795 published?
CVE-2023-48795 was published on December 20, 2023.