CVE-2023-28531
Gentoo Linux Security Advisory 202307-01
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
Fabian Bäumer, Marcus Brinkmann, Joerg Schwenk discovered that the SSH protocol was vulnerable to a prefix truncation attack. If a remote attacker was able to intercept SSH communications, extension negotiation messages could be truncated, possibly leading to certain algorithms and features being downgraded. This issue is known as the Terrapin attack. This update adds protocol extensions to mitigate this issue. Luci Stanescu discovered that OpenSSH incorrectly added destination constraints when smartcard keys were added to ssh-agent, contrary to expectations. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 23.04.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-03-17 CVE Reserved
- 2023-03-17 CVE Published
- 2024-08-02 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20230413-0008 | Third Party Advisory |
|
https://www.openwall.com/lists/oss-security/2023/03/15/8 | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openbsd Search vendor "Openbsd" | Openssh Search vendor "Openbsd" for product "Openssh" | >= 8.9 < 9.3 Search vendor "Openbsd" for product "Openssh" and version " >= 8.9 < 9.3" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Brocade Fabric Operating System Search vendor "Netapp" for product "Brocade Fabric Operating System" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Hci Bootstrap Os Search vendor "Netapp" for product "Hci Bootstrap Os" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Solidfire Element Os Search vendor "Netapp" for product "Solidfire Element Os" | - | - |
Affected
|