QID 996391

Date Published: 2023-12-20

QID 996391: Python (Pip) Security Update for golang.org/x/crypto (GHSA-45x7-px36-x8w8)

Terrapin is a prefix truncation attack targeting the SSH protocol. More precisely, Terrapin breaks the integrity of SSH's secure channel. By carefully adjusting the sequence numbers during the handshake, an attacker can remove an arbitrary amount of messages sent by the client or server at the beginning of the secure channel without the client or server noticing it.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-45x7-px36-x8w8 for updates and patch information.
    Vendor References

    CVEs related to QID 996391

    Software Advisories
    Advisory ID Software Component Link
    GHSA-45x7-px36-x8w8 golang.org/x/crypto URL Logo github.com/advisories/GHSA-45x7-px36-x8w8