• 公告ID (KylinSec-SA-2024-3478)

摘要:

Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which
some security features have been downgraded or disabled, aka a Terrapin
attack

The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.

安全等级: Low

公告ID: KylinSec-SA-2024-3478

发布日期: 2024年8月30日

关联CVE: CVE-2024-41909  

  • 详细介绍

1. 漏洞描述

   

Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which
some security features have been downgraded or disabled, aka a Terrapin
attack

The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2024-41909 KY3.4-5A apache-sshd Unaffected
CVE-2024-41909 KY3.5.2 apache-sshd Unaffected
CVE-2024-41909 V6 apache-sshd Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-3477 下一篇:KylinSec-SA-2024-3479