Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 9 MGASA-2024-0015 Critical: Fix for SSH Prefix Truncation Attack

mageia
Calendar Grey January 19, 2024
Dist Mageia Esm H88
New improvements in Erlang packages boost the security measures for Mageia systems by tackling the SSH Prefix Truncation Vulnerability.
The updated packages fix a security vulnerability: Prefix Truncation Attacks in SSH Specification (Terrapin Attack): erlang-ssh

Summary

The updated packages fix a security vulnerability: Prefix Truncation Attacks in SSH Specification (Terrapin Attack): erlang-ssh. (CVE-2023-48795)

References

- https://bugs.mageia.org/show_bug.cgi?id=32670

- https://www.openwall.com/lists/oss-security/2023/12/18/3

- https://www.openwall.com/lists/oss-security/2023/12/19/5

- https://www.openwall.com/lists/oss-security/2023/12/20/3

- https://www.cve.org/CVERecord?id=CVE-2023-48795

Resolution

SRPMS

- 9/core/erlang-24.3.4.15-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 19 Jan 2024
URL: https://advisories.mageia.org/MGASA-2024-0015.html
Type: security
CVE: CVE-2023-48795

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here