Bug#1059294: trilead-ssh2: CVE-2023-48795

2025-02-18 Thread Andreas Tille
Hi, since trilead-ssh2 came up as a candidate for the Bug of the Day[1]. I realised the watch file was outdated and pointed it to Github where a long series of newer releases was tagged. Unfortunately the version string is a bit unfortunate and we might need an epoch most probably. I found some

Bug#1059294: trilead-ssh2: CVE-2023-48795

2023-12-22 Thread Moritz Mühlenhoff
Source: trilead-ssh2 X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability should also affect Trilead SSH: https://terrapin-attack.com/ CVE-2023-48795[0]: | The SSH transport protocol with certain OpenSSH extensions, found in | OpenSSH before 9