RE: SSH Terrapin Prefix Truncation Weakness (CVE-2023-48795) on Red Hat Enterprise Linux release 8.7 (Ootpa)
"'Ben Argyle' via
[email protected]" <
[email protected]>
Tue, 23 Jan 2024 16:32:04 +0000
| Newsgroups |
gmane.linux.redhat.general |
| Message-ID |
<LO6P265MB7333F3152BBB4E4290BFE99D8B742@LO6P265MB7333.GBRP265.PROD.OUTLOOK.COM> |
--_000_LO6P265MB7333F3152BBB4E4290BFE99D8B742LO6P265MB7333GBRP_
Content-Type: text/plain; charset="UTF-8"
There's a mitigation here: https://access.redhat.com/security/cve/CVE-2023-48795
Ben
From: Kaushal Shriyan <[email protected]>
Sent: 23 January 2024 16:02
To: General Red Hat Linux discussion list <[email protected]>
Subject: SSH Terrapin Prefix Truncation Weakness (CVE-2023-48795) on Red Hat Enterprise Linux release 8.7 (Ootpa)
Hi,
I have the SSH Terrapin Prefix Truncation Weakness on Red Hat Enterprise Linux release 8.7 (Ootpa). The details are as follows.
# rpm -qa | grep openssh
openssh-8.0p1-16.el8.x86_64
openssh-askpass-8.0p1-16.el8.x86_64
openssh-server-8.0p1-16.el8.x86_64
openssh-clients-8.0p1-16.el8.x86_64
# cat /etc/redhat-release
Red Hat Enterprise Linux release 8.7 (Ootpa)
#
SSH Terrapin Prefix Truncation Weakness (CVE-2023-48795)
Synopsis
The remote SSH server is vulnerable to a mitm prefix truncation attack.
Description
The remote SSH server is vulnerable to a man-in-the-middle prefix truncation weakness known as Terrapin.
This can allow a remote, man-in-the-middle attacker to bypass integrity checks and downgrade the
connection's security.
Note that this plugin only checks for remote SSH servers that support either ChaCha20-Poly1305 or CBC
with Encrypt-then-MAC and do not support the strict key exchange countermeasures. It does not check for
vulnerable software versions.
See Also
https://terrapin-attack.com/
Solution
Contact the vendor for an update with the strict key exchange countermeasures or disable the affected
algorithms.
Risk Factor
Medium
CVSS v3.0 Base Score
5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
CVSS v3.0 Temporal Score
5.3 (CVSS:3.0/E:P/RL:O/RC:C)
VPR Score
6.9
CVSS v2.0 Base Score
5.4 (CVSS2#AV:N/AC:H/Au:N/C:N/I:C/A:N)
CVSS v2.0 Temporal Score
4.2 (CVSS2#E:POC/RL:OF/RC:C)
187315 (10) - SSH Terrapin Prefix Truncation Weakness (CVE-2023-48795) 16
References
CVE CVE-2023-48795
Is there a way to configure /etc/ssh/sshd_config to mitigate SSH Terrapin Prefix Truncation Weakness (CVE-2023-48795)
Please guide me.
Thanks in advance.
Best Regards,
Kaushal
--
You received this message because you are subscribed to the Google Groups "[email protected]<mailto:[email protected]>" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]<mailto:[email protected]>.
--
You received this message because you are subscribed to the Google Groups "[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
--_000_LO6P265MB7333F3152BBB4E4290BFE99D8B742LO6P265MB7333GBRP_
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p
{mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0cm;
mso-margin-bottom-alt:auto;
margin-left:0cm;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
mso-margin-top-alt:auto;
margin-right:0cm;
mso-margin-bottom-alt:auto;
margin-left:0cm;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
span.EmailStyle19
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:black;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;
mso-fareast-language:EN-US;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-GB" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><font size=3D"2" color=3D"black" face=3D"Calibri"><s=
pan style=3D"font-size:11.0pt;font-family:"Calibri",sans-serif;co=
lor:black;mso-fareast-language:EN-US">There's a mitigation here:
<a href=3D"https://access.redhat.com/security/cve/CVE-2023-48795">https://a=
ccess.redhat.com/security/cve/CVE-2023-48795</a><o:p></o:p></span></font></=
p>
<p class=3D"MsoNormal"><font size=3D"2" color=3D"black" face=3D"Calibri"><s=
pan style=3D"font-size:11.0pt;font-family:"Calibri",sans-serif;co=
lor:black;mso-fareast-language:EN-US"><o:p> </o:p></span></font></p>
<p class=3D"MsoNormal"><font size=3D"2" color=3D"black" face=3D"Calibri"><s=
pan style=3D"font-size:11.0pt;font-family:"Calibri",sans-serif;co=
lor:black;mso-fareast-language:EN-US">Ben<o:p></o:p></span></font></p>
<p class=3D"MsoNormal"><font size=3D"2" color=3D"black" face=3D"Calibri"><s=
pan style=3D"font-size:11.0pt;font-family:"Calibri",sans-serif;co=
lor:black;mso-fareast-language:EN-US"><o:p> </o:p></span></font></p>
<p class=3D"MsoNormal"><b><font size=3D"2" face=3D"Calibri"><span lang=3D"E=
N-US" style=3D"font-size:11.0pt;font-family:"Calibri",sans-serif;=
font-weight:bold">From:</span></font></b><font size=3D"2" face=3D"Calibri">=
<span lang=3D"EN-US" style=3D"font-size:11.0pt;font-family:"Calibri&qu=
ot;,sans-serif">
Kaushal Shriyan <[email protected]> <br>
<b><span style=3D"font-weight:bold">Sent:</span></b> 23 January 2024 16:02<=
br>
<b><span style=3D"font-weight:bold">To:</span></b> General Red Hat Linux di=
scussion list <[email protected]><br>
<b><span style=3D"font-weight:bold">Subject:</span></b> SSH Terrapin Prefix=
Truncation Weakness (CVE-2023-48795) on Red Hat Enterprise Linux release 8=
.7 (Ootpa)<o:p></o:p></span></font></p>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt"><o:p> </o:p></span></font></p>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt">Hi,<o:p></o:p></span></font></p>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt"><o:p> </o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt">I have the SSH Terrapin Prefix Truncation Weakness o=
n Red Hat Enterprise Linux release 8.7 (Ootpa). The details are as fol=
lows. <o:p></o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt"><o:p> </o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><font size=3D"3" face=
=3D"Times New Roman"><span style=3D"font-size:12.0pt"># rpm -qa | grep open=
ssh<br>
openssh-8.0p1-16.el8.x86_64<br>
openssh-askpass-8.0p1-16.el8.x86_64<br>
openssh-server-8.0p1-16.el8.x86_64<br>
openssh-clients-8.0p1-16.el8.x86_64<o:p></o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt"># cat /etc/redhat-release<br>
Red Hat Enterprise Linux release 8.7 (Ootpa)<br>
#<o:p></o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt"><o:p> </o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt">SSH Terrapin Prefix Truncation Weakness (CVE-2023-48=
795)<br>
<br>
Synopsis<br>
The remote SSH server is vulnerable to a mitm prefix truncation attack.<br>
Description<br>
The remote SSH server is vulnerable to a man-in-the-middle prefix truncatio=
n weakness known as Terrapin.<br>
This can allow a remote, man-in-the-middle attacker to bypass integrity che=
cks and downgrade the<br>
connection's security.<br>
Note that this plugin only checks for remote SSH servers that support eithe=
r ChaCha20-Poly1305 or CBC<br>
with Encrypt-then-MAC and do not support the strict key exchange countermea=
sures. It does not check for<br>
vulnerable software versions.<br>
See Also<br>
<a href=3D"https://terrapin-attack.com/">https://terrapin-attack.com/</a><b=
r>
<br>
Solution<br>
Contact the vendor for an update with the strict key exchange countermeasur=
es or disable the affected<br>
algorithms.<br>
Risk Factor<br>
Medium<br>
CVSS v3.0 Base Score<br>
5.9 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)<br>
CVSS v3.0 Temporal Score<br>
5.3 (CVSS:3.0/E:P/RL:O/RC:C)<br>
VPR Score<br>
6.9<br>
CVSS v2.0 Base Score<br>
5.4 (CVSS2#AV:N/AC:H/Au:N/C:N/I:C/A:N)<br>
CVSS v2.0 Temporal Score<br>
4.2 (CVSS2#E:POC/RL:OF/RC:C)<br>
187315 (10) - SSH Terrapin Prefix Truncation Weakness (CVE-2023-48795) 16<b=
r>
<br>
References<br>
CVE CVE-2023-48795<o:p></o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt"><o:p> </o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt">Is there a way to configure /etc/ssh/sshd_config to =
mitigate SSH Terrapin Prefix Truncation Weakness (CVE-2023-48795)<o:p></o:p=
></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt"><o:p> </o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt">Please guide me.<o:p></o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt"><o:p> </o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt">Thanks in advance.<o:p></o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt"><o:p> </o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt">Best Regards,<o:p></o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt"><o:p> </o:p></span></font></p>
</div>
<div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt">Kaushal<o:p></o:p></span></font></p>
</div>
</div>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:12.0pt">--
<br>
You received this message because you are subscribed to the Google Groups &=
quot;<a href=3D"mailto:[email protected]">[email protected]</a>&q=
uot; group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to
<a href=3D"mailto:[email protected]">redhat-list+unsubscri=
[email protected]</a>.<o:p></o:p></span></font></p>
</div>
</body>
</html>
<p></p>
-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;[email protected]" group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">redhat-list+u=
[email protected]</a>.<br />
--_000_LO6P265MB7333F3152BBB4E4290BFE99D8B742LO6P265MB7333GBRP_--