diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml new file mode 100644 index 000000000000..82db275e300c --- /dev/null +++ b/security/vuxml/vuln/2024.xml @@ -0,0 +1,33 @@ + + FreeBSD -- Prefix Truncation Attack in the SSH protocol + + + FreeBSD + 14.014.0_4 + 13.213.2_9 + + + + +

Problem Description:

+

The SSH protocol executes an initial handshake between the + server and the client. This protocol handshake includes the + possibility of several extensions allowing different options to be + selected. Validation of the packets in the handshake is done through + sequence numbers.

+

Impact:

+

A man in the middle attacker can silently manipulate handshake + messages to truncate extension negotiation messages potentially + leading to less secure client authentication algorithms or deactivating + keystroke timing attack countermeasures.

+ +
+ + CVE-2023-48795 + SA-23:19.openssh + + + 2023-12-19 + 2024-01-02 + +