From f7bc073956657c32ac3ce3b6bb0767c887593b44 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 18 Dec 2023 21:39:15 +0000 Subject: [PATCH] Publish GHSA-45x7-px36-x8w8 --- .../GHSA-45x7-px36-x8w8.json | 87 +++++++++++++++++++ 1 file changed, 87 insertions(+) diff --git a/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json b/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json index 637a2592c53..18ed2e6ef0b 100644 --- a/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json +++ b/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json @@ -33,6 +33,25 @@ ] } ] + }, + { + "package": { + "ecosystem": "Go", + "name": "golang.org/x/crypto" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.17.0" + } + ] + } + ] } ], "references": [ @@ -44,10 +63,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48795" }, + { + "type": "WEB", + "url": "https://github.com/mwiede/jsch/issues/457" + }, { "type": "WEB", "url": "https://github.com/paramiko/paramiko/issues/2337" }, + { + "type": "WEB", + "url": "https://github.com/mwiede/jsch/pull/461" + }, { "type": "WEB", "url": "https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0" @@ -60,10 +87,42 @@ "type": "WEB", "url": "https://github.com/warp-tech/russh/commit/1aa340a7df1d5be1c0f4a9e247aade76dfdd2951" }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/cve-2023-48795" + }, + { + "type": "WEB", + "url": "https://bugs.gentoo.org/920280" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254210" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=1217950" + }, + { + "type": "WEB", + "url": "https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-45x7-px36-x8w8" + }, + { + "type": "WEB", + "url": "https://github.com/drakkan/sftpgo/releases/tag/v2.5.6" + }, { "type": "WEB", "url": "https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42" }, + { + "type": "WEB", + "url": "https://github.com/erlang/otp/releases/tag/OTP-26.2.1" + }, { "type": "WEB", "url": "https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25" @@ -92,6 +151,14 @@ "type": "WEB", "url": "https://gitlab.com/libssh/libssh-mirror/-/tags" }, + { + "type": "WEB", + "url": "https://go.dev/cl/550715" + }, + { + "type": "WEB", + "url": "https://go.dev/issue/64784" + }, { "type": "WEB", "url": "https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ" @@ -116,6 +183,18 @@ "type": "WEB", "url": "https://news.ycombinator.com/item?id=38685286" }, + { + "type": "WEB", + "url": "https://security-tracker.debian.org/tracker/CVE-2023-48795" + }, + { + "type": "WEB", + "url": "https://security-tracker.debian.org/tracker/source-package/libssh2" + }, + { + "type": "WEB", + "url": "https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg" + }, { "type": "WEB", "url": "https://thorntech.com/cve-2023-48795-and-sftp-gateway/" @@ -124,6 +203,10 @@ "type": "WEB", "url": "https://twitter.com/TrueSkrillor/status/1736774389725565005" }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/CVE-2023-48795" + }, { "type": "WEB", "url": "https://www.bitvise.com/ssh-server-version-history" @@ -148,6 +231,10 @@ "type": "WEB", "url": "https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/" }, + { + "type": "WEB", + "url": "https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/" + }, { "type": "WEB", "url": "https://www.terrapin-attack.com"