Re: Terrapin

Brian Pence <[email protected]> Wed, 27 Dec 2023 09:08:46 -0600
Newsgroups gmane.ietf.secsh
Message-ID <CABE+0ouVOPfbfWtZKZSA2SRcxsuQP-RMbXN9-xFmmoh=NF0jTw@mail.gmail.com>
--000000000000a24936060d7f2d2e
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

And at least one claim that some implementations knew about this about a
month before public disclosure, so they were working on 'strict kex' for a
while.

This protocol vulnerability was pre-disclosed to us by Fabian B=C3=A4umer,
Marcus Brinkmann, and J=C3=B6rg Schwenk, on 17 November 2023. For full deta=
ils
of their report, see their dedicated website about the Terrapin attack
<https://terrapin-attack.com/>.


Brian Pence
Celestial Software
901-283-1970 <http://voice.google.com/calls?a=3Dnc,%2B19012831970>
http://www.celestialsoftware.net


On Wed, Dec 27, 2023 at 9:06=E2=80=AFAM Brian Pence <bpence@celestialsoftwa=
re.net>
wrote:

> This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT,
> Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before
> 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh
> before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4=
.6,
>
> Then each of the 'fixed' packages will have some kind of documentation
> describing their use of 'strict kex'
> For example putty 0.80:
>
> https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-terrapin=
.html
>
> To mitigate the vulnerability, the OpenSSH project has defined a SSH
> extension called 'strict KEX' (documented in their PROTOCOL
> <https://cvsweb.openbsd.org/src/usr.bin/ssh/PROTOCOL?rev=3DHEAD&content-t=
ype=3Dtext/x-cvsweb-markup> document),
> which PuTTY 0.80 implements.
>
>
>
>
> Brian Pence
> Celestial Software
> 901-283-1970 <http://voice.google.com/calls?a=3Dnc,%2B19012831970>
> http://www.celestialsoftware.net
>
>
> On Mon, Dec 25, 2023 at 1:58=E2=80=AFAM Peter Gutmann <[email protected]=
d.ac.nz>
> wrote:
>
>> Brian Pence <[email protected]> writes:
>>
>> >Related publication at NIST:
>> https://nvd.nist.gov/vuln/detail/CVE-2023-48795
>> >
>> >Implementation versions that are identified as NOT VULNERABLE have all
>> >recently implemented "strict key exchange"
>>
>> Where are you seeing that?  I can't find that text anywhere on the page.
>>
>> Peter.
>>
>>

--000000000000a24936060d7f2d2e
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>And at least one claim that some implementations knew=
 about this about a month before public disclosure, so they were working on=
 &#39;strict kex&#39; for a while.</div><div><p style=3D"color:rgb(0,0,0);f=
ont-family:&quot;Times New Roman&quot;;font-size:medium">This protocol vuln=
erability was pre-disclosed to us by Fabian=C2=A0B=C3=A4umer, Marcus=C2=A0B=
rinkmann, and J=C3=B6rg=C2=A0Schwenk, on 17 November 2023. For full details=
 of their report, see their=C2=A0<a href=3D"https://terrapin-attack.com/">d=
edicated website about the Terrapin attack</a>.</p><br class=3D"gmail-Apple=
-interchange-newline"></div><br clear=3D"all"><div><div dir=3D"ltr" class=
=3D"gmail_signature" data-smartmail=3D"gmail_signature"><div dir=3D"ltr"><d=
iv>Brian Pence</div><div>Celestial Software</div><div>901-283-1970<a href=
=3D"http://voice.google.com/calls?a=3Dnc,%2B19012831970" class=3D"gv-tel-li=
nk" target=3D"_blank" rel=3D"noopener" title=3D"Call +1 901-283-1970 via Go=
ogle Voice"></a></div><div><a href=3D"http://www.celestialsoftware.net" tar=
get=3D"_blank">http://www.celestialsoftware.net</a></div></div></div></div>=
<br></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_at=
tr">On Wed, Dec 27, 2023 at 9:06=E2=80=AFAM Brian Pence &lt;<a href=3D"mail=
to:[email protected]">[email protected]</a>&gt; wrote=
:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.=
8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=3D"lt=
r"><span style=3D"color:rgb(51,51,51);font-family:&quot;Source Sans Pro&quo=
t;,Helvetica,Arial,sans-serif;font-size:16.96px">This also affects Maverick=
 Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh =
before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, <a h=
ref=3D"http://golang.org/x/crypto" target=3D"_blank">golang.org/x/crypto</a=
> before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech S=
FTP Gateway before 3.4.6,</span><div><font color=3D"#333333" face=3D"Source=
 Sans Pro, Helvetica, Arial, sans-serif"><span style=3D"font-size:16.96px">=
<br></span></font></div><div><font color=3D"#333333" face=3D"Source Sans Pr=
o, Helvetica, Arial, sans-serif"><span style=3D"font-size:16.96px">Then eac=
h of the &#39;fixed&#39; packages will have some kind of documentation desc=
ribing their use of &#39;strict kex&#39;</span></font></div><div><font colo=
r=3D"#333333" face=3D"Source Sans Pro, Helvetica, Arial, sans-serif"><span =
style=3D"font-size:16.96px">For example putty 0.80:</span></font></div><div=
><a href=3D"https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vul=
n-terrapin.html" target=3D"_blank">https://www.chiark.greenend.org.uk/~sgta=
tham/putty/wishlist/vuln-terrapin.html</a><font color=3D"#333333" face=3D"S=
ource Sans Pro, Helvetica, Arial, sans-serif"><span style=3D"font-size:16.9=
6px"><br></span></font></div><div><p style=3D"color:rgb(0,0,0);font-family:=
&quot;Times New Roman&quot;;font-size:medium">To mitigate the vulnerability=
, the OpenSSH project has defined a SSH extension called &#39;strict KEX&#3=
9; (documented in their=C2=A0<a href=3D"https://cvsweb.openbsd.org/src/usr.=
bin/ssh/PROTOCOL?rev=3DHEAD&amp;content-type=3Dtext/x-cvsweb-markup" target=
=3D"_blank">PROTOCOL</a>=C2=A0document), which PuTTY 0.80 implements.</p><p=
 style=3D"color:rgb(0,0,0);font-family:&quot;Times New Roman&quot;;font-siz=
e:medium"><br></p></div><div><font color=3D"#333333" face=3D"Source Sans Pr=
o, Helvetica, Arial, sans-serif"><span style=3D"font-size:16.96px"><br></sp=
an></font></div><div><font color=3D"#333333" face=3D"Source Sans Pro, Helve=
tica, Arial, sans-serif"><span style=3D"font-size:16.96px"><br clear=3D"all=
"></span></font><div><div dir=3D"ltr" class=3D"gmail_signature"><div dir=3D=
"ltr"><div>Brian Pence</div><div>Celestial Software</div><div>901-283-1970<=
a href=3D"http://voice.google.com/calls?a=3Dnc,%2B19012831970" rel=3D"noope=
ner" title=3D"Call +1 901-283-1970 via Google Voice" target=3D"_blank"></a>=
</div><div><a href=3D"http://www.celestialsoftware.net" target=3D"_blank">h=
ttp://www.celestialsoftware.net</a></div></div></div></div><br></div></div>=
<br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Mon=
, Dec 25, 2023 at 1:58=E2=80=AFAM Peter Gutmann &lt;<a href=3D"mailto:pgut0=
[email protected]" target=3D"_blank">[email protected]</a>&gt; w=
rote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0p=
x 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Brian Penc=
e &lt;<a href=3D"mailto:[email protected]" target=3D"_blank">bpe=
[email protected]</a>&gt; writes:<br>
<br>
&gt;Related publication at NIST: <a href=3D"https://nvd.nist.gov/vuln/detai=
l/CVE-2023-48795" rel=3D"noreferrer" target=3D"_blank">https://nvd.nist.gov=
/vuln/detail/CVE-2023-48795</a><br>
&gt;<br>
&gt;Implementation versions that are identified as NOT VULNERABLE have all<=
br>
&gt;recently implemented &quot;strict key exchange&quot;<br>
<br>
Where are you seeing that?=C2=A0 I can&#39;t find that text anywhere on the=
 page.<br>
<br>
Peter.<br>
<br>
</blockquote></div>
</blockquote></div>

--000000000000a24936060d7f2d2e--