QID 996391
Date Published: 2023-12-20
QID 996391: Python (Pip) Security Update for golang.org/x/crypto (GHSA-45x7-px36-x8w8)
Terrapin is a prefix truncation attack targeting the SSH protocol. More precisely, Terrapin breaks the integrity of SSH's secure channel. By carefully adjusting the sequence numbers during the handshake, an attacker can remove an arbitrary amount of messages sent by the client or server at the beginning of the secure channel without the client or server noticing it.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-45x7-px36-x8w8 for updates and patch information.
Vendor References
- GHSA-45x7-px36-x8w8 -
github.com/advisories/GHSA-45x7-px36-x8w8
CVEs related to QID 996391
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-45x7-px36-x8w8 | golang.org/x/crypto |
|