QID 996349

Date Published: 2023-12-19

QID 996349: GO (Go) Security Update for golang.org/x/crypto (GHSA-45x7-px36-x8w8)

Russh v0.40.1 and earlier is vulnerable to a novel prefix truncation attack (a.k.a. Terrapin attack), which allows a man-in-the-middle attacker to strip an arbitrary number of messages right after the initial key exchange, breaking SSH extension negotiation (RFC8308) in the process and thus downgrading connection security.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-45x7-px36-x8w8 for updates and patch information.
    Vendor References

    CVEs related to QID 996349

    Software Advisories
    Advisory ID Software Component Link
    GHSA-45x7-px36-x8w8 golang.org/x/crypto URL Logo github.com/advisories/GHSA-45x7-px36-x8w8