Re: Terrapin

Brian Pence <[email protected]> Wed, 27 Dec 2023 09:06:45 -0600
Newsgroups gmane.ietf.secsh
Message-ID <CABE+0ouCRBosAmJmOhTrhNkKLrLLEBdEhORp2J4-8rDpKz6kPA@mail.gmail.com>
--000000000000695a83060d7f264e
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT,
Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before
0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh
before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6=
,

Then each of the 'fixed' packages will have some kind of documentation
describing their use of 'strict kex'
For example putty 0.80:
https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-terrapin.h=
tml

To mitigate the vulnerability, the OpenSSH project has defined a SSH
extension called 'strict KEX' (documented in their PROTOCOL
<https://cvsweb.openbsd.org/src/usr.bin/ssh/PROTOCOL?rev=3DHEAD&content-typ=
e=3Dtext/x-cvsweb-markup>
document),
which PuTTY 0.80 implements.




Brian Pence
Celestial Software
901-283-1970 <http://voice.google.com/calls?a=3Dnc,%2B19012831970>
http://www.celestialsoftware.net


On Mon, Dec 25, 2023 at 1:58=E2=80=AFAM Peter Gutmann <[email protected].=
ac.nz>
wrote:

> Brian Pence <[email protected]> writes:
>
> >Related publication at NIST:
> https://nvd.nist.gov/vuln/detail/CVE-2023-48795
> >
> >Implementation versions that are identified as NOT VULNERABLE have all
> >recently implemented "strict key exchange"
>
> Where are you seeing that?  I can't find that text anywhere on the page.
>
> Peter.
>
>

--000000000000695a83060d7f264e
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><span style=3D"color:rgb(51,51,51);font-family:&quot;Sourc=
e Sans Pro&quot;,Helvetica,Arial,sans-serif;font-size:16.96px">This also af=
fects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through=
 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH befor=
e 2.14.2, <a href=3D"http://golang.org/x/crypto">golang.org/x/crypto</a> be=
fore 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP =
Gateway before 3.4.6,</span><div><font color=3D"#333333" face=3D"Source San=
s Pro, Helvetica, Arial, sans-serif"><span style=3D"font-size:16.96px"><br>=
</span></font></div><div><font color=3D"#333333" face=3D"Source Sans Pro, H=
elvetica, Arial, sans-serif"><span style=3D"font-size:16.96px">Then each of=
 the &#39;fixed&#39; packages will have some kind of documentation describi=
ng their use of &#39;strict kex&#39;</span></font></div><div><font color=3D=
"#333333" face=3D"Source Sans Pro, Helvetica, Arial, sans-serif"><span styl=
e=3D"font-size:16.96px">For example putty 0.80:</span></font></div><div><a =
href=3D"https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-te=
rrapin.html">https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vu=
ln-terrapin.html</a><font color=3D"#333333" face=3D"Source Sans Pro, Helvet=
ica, Arial, sans-serif"><span style=3D"font-size:16.96px"><br></span></font=
></div><div><p style=3D"color:rgb(0,0,0);font-family:&quot;Times New Roman&=
quot;;font-size:medium">To mitigate the vulnerability, the OpenSSH project =
has defined a SSH extension called &#39;strict KEX&#39; (documented in thei=
r=C2=A0<a href=3D"https://cvsweb.openbsd.org/src/usr.bin/ssh/PROTOCOL?rev=
=3DHEAD&amp;content-type=3Dtext/x-cvsweb-markup">PROTOCOL</a>=C2=A0document=
), which PuTTY 0.80 implements.</p><p style=3D"color:rgb(0,0,0);font-family=
:&quot;Times New Roman&quot;;font-size:medium"><br></p></div><div><font col=
or=3D"#333333" face=3D"Source Sans Pro, Helvetica, Arial, sans-serif"><span=
 style=3D"font-size:16.96px"><br></span></font></div><div><font color=3D"#3=
33333" face=3D"Source Sans Pro, Helvetica, Arial, sans-serif"><span style=
=3D"font-size:16.96px"><br clear=3D"all"></span></font><div><div dir=3D"ltr=
" class=3D"gmail_signature" data-smartmail=3D"gmail_signature"><div dir=3D"=
ltr"><div>Brian Pence</div><div>Celestial Software</div><div>901-283-1970<a=
 href=3D"http://voice.google.com/calls?a=3Dnc,%2B19012831970" class=3D"gv-t=
el-link" target=3D"_blank" rel=3D"noopener" title=3D"Call +1 901-283-1970 v=
ia Google Voice"></a></div><div><a href=3D"http://www.celestialsoftware.net=
" target=3D"_blank">http://www.celestialsoftware.net</a></div></div></div><=
/div><br></div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=
=3D"gmail_attr">On Mon, Dec 25, 2023 at 1:58=E2=80=AFAM Peter Gutmann &lt;<=
a href=3D"mailto:[email protected]">[email protected]</a>&g=
t; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0p=
x 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Brian =
Pence &lt;<a href=3D"mailto:[email protected]" target=3D"_blank"=
>[email protected]</a>&gt; writes:<br>
<br>
&gt;Related publication at NIST: <a href=3D"https://nvd.nist.gov/vuln/detai=
l/CVE-2023-48795" rel=3D"noreferrer" target=3D"_blank">https://nvd.nist.gov=
/vuln/detail/CVE-2023-48795</a><br>
&gt;<br>
&gt;Implementation versions that are identified as NOT VULNERABLE have all<=
br>
&gt;recently implemented &quot;strict key exchange&quot;<br>
<br>
Where are you seeing that?=C2=A0 I can&#39;t find that text anywhere on the=
 page.<br>
<br>
Peter.<br>
<br>
</blockquote></div>

--000000000000695a83060d7f264e--