USN-6585-1: libssh2 vulnerability
Fabian Bäumer, Marcus Brinkmann, Jörg Schwenk discovered that the SSH protocol was vulnerable to a prefix truncation attack. If a remote attacker was able to intercept SSH communications, extension negotiation messages could be truncated, possibly leading to certain algorithms and features being downgraded. This issue is known as the Terrapin attack. This update adds protocol extensions to mitigate this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6585-1?
The severity of USN-6585-1 is considered to be high due to the potential impact of intercepted SSH communications.
How do I fix USN-6585-1?
To fix USN-6585-1, upgrade the libssh2-1 package to version 1.11.0-2ubuntu0.1 or later.
What systems are affected by USN-6585-1?
USN-6585-1 affects Ubuntu 23.10 systems running the vulnerable version of libssh2-1.
What exploitation vectors are associated with USN-6585-1?
USN-6585-1 can be exploited through a prefix truncation attack allowing a remote attacker to intercept and manipulate SSH communications.
What are the potential consequences of USN-6585-1 if left unpatched?
If left unpatched, USN-6585-1 could lead to unauthorized access and manipulation of SSH sessions.