SSH Terrapin Prefix Truncation Weakness (CVE-2023-48795) on Red Hat Enterprise Linux release 8.7 (Ootpa)

Kaushal Shriyan <[email protected]> Tue, 23 Jan 2024 21:32:03 +0530
Newsgroups gmane.linux.redhat.general
Message-ID <CAD7Ssm_wLiX0fvV2ZJ4MX9J8_e=9=-ygU4ShzQAfcx1Hkj03NA@mail.gmail.com>
--000000000000fd032a060f9f11b7
Content-Type: text/plain; charset="UTF-8"

Hi,

I have the SSH Terrapin Prefix Truncation Weakness on Red Hat Enterprise
Linux release 8.7 (Ootpa). The details are as follows.

# rpm -qa | grep openssh
openssh-8.0p1-16.el8.x86_64
openssh-askpass-8.0p1-16.el8.x86_64
openssh-server-8.0p1-16.el8.x86_64
openssh-clients-8.0p1-16.el8.x86_64

# cat /etc/redhat-release
Red Hat Enterprise Linux release 8.7 (Ootpa)
#

SSH Terrapin Prefix Truncation Weakness (CVE-2023-48795)

Synopsis
The remote SSH server is vulnerable to a mitm prefix truncation attack.
Description
The remote SSH server is vulnerable to a man-in-the-middle prefix
truncation weakness known as Terrapin.
This can allow a remote, man-in-the-middle attacker to bypass integrity
checks and downgrade the
connection's security.
Note that this plugin only checks for remote SSH servers that support
either ChaCha20-Poly1305 or CBC
with Encrypt-then-MAC and do not support the strict key exchange
countermeasures. It does not check for
vulnerable software versions.
See Also
https://terrapin-attack.com/

Solution
Contact the vendor for an update with the strict key exchange
countermeasures or disable the affected
algorithms.
Risk Factor
Medium
CVSS v3.0 Base Score
5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
5.3 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.9
CVSS v2.0 Base Score
5.4 (CVSS2#AV:N/AC:H/Au:N/C:N/I:C/A:N)
CVSS v2.0 Temporal Score
4.2 (CVSS2#E:POC/RL:OF/RC:C)
187315 (10) - SSH Terrapin Prefix Truncation Weakness (CVE-2023-48795) 16

References
CVE CVE-2023-48795

Is there a way to configure /etc/ssh/sshd_config to mitigate SSH Terrapin
Prefix Truncation Weakness (CVE-2023-48795)

Please guide me.

Thanks in advance.

Best Regards,

Kaushal

-- 
You received this message because you are subscribed to the Google Groups "[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].

--000000000000fd032a060f9f11b7
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi,<br><div><br></div><div>I have the SSH Terrapin Prefix =
Truncation Weakness on=C2=A0Red Hat Enterprise Linux release 8.7 (Ootpa). T=
he details are as follows.=C2=A0</div><div><br></div><div># rpm -qa | grep =
openssh<br>openssh-8.0p1-16.el8.x86_64<br>openssh-askpass-8.0p1-16.el8.x86_=
64<br>openssh-server-8.0p1-16.el8.x86_64<br>openssh-clients-8.0p1-16.el8.x8=
6_64<br><br></div><div># cat /etc/redhat-release<br>Red Hat Enterprise Linu=
x release 8.7 (Ootpa)<br>#<br></div><div><br></div><div>SSH Terrapin Prefix=
 Truncation Weakness (CVE-2023-48795)<br><br>Synopsis<br>The remote SSH ser=
ver is vulnerable to a mitm prefix truncation attack.<br>Description<br>The=
 remote SSH server is vulnerable to a man-in-the-middle prefix truncation w=
eakness known as Terrapin.<br>This can allow a remote, man-in-the-middle at=
tacker to bypass integrity checks and downgrade the<br>connection&#39;s sec=
urity.<br>Note that this plugin only checks for remote SSH servers that sup=
port either ChaCha20-Poly1305 or CBC<br>with Encrypt-then-MAC and do not su=
pport the strict key exchange countermeasures. It does not check for<br>vul=
nerable software versions.<br>See Also<br><a href=3D"https://terrapin-attac=
k.com/">https://terrapin-attack.com/</a><br><br>Solution<br>Contact the ven=
dor for an update with the strict key exchange countermeasures or disable t=
he affected<br>algorithms.<br>Risk Factor<br>Medium<br>CVSS v3.0 Base Score=
<br>5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)<br>CVSS v3.0 Tempora=
l Score<br>5.3 (CVSS:3.0/E:P/RL:O/RC:C)<br>VPR Score<br>6.9<br>CVSS v2.0 Ba=
se Score<br>5.4 (CVSS2#AV:N/AC:H/Au:N/C:N/I:C/A:N)<br>CVSS v2.0 Temporal Sc=
ore<br>4.2 (CVSS2#E:POC/RL:OF/RC:C)<br>187315 (10) - SSH Terrapin Prefix Tr=
uncation Weakness (CVE-2023-48795) 16<br><br>References<br>CVE CVE-2023-487=
95<br></div><div><br></div><div>Is there a way to configure /etc/ssh/sshd_c=
onfig to mitigate SSH Terrapin Prefix Truncation Weakness (CVE-2023-48795)<=
/div><div><br></div><div>Please guide me.</div><div><br></div><div>Thanks i=
n advance.</div><div><br></div><div>Best Regards,</div><div><br></div><div>=
Kaushal</div></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;[email protected]&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">redhat-list+u=
[email protected]</a>.<br />

--000000000000fd032a060f9f11b7--