Updated filezilla packages fix a security vulnerability ("Terrapin attack")
Publication date: 10 Feb 2024Modification date: 10 Feb 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-48795
Description
Fabian Baeumer, Marcus Brinkmann and Joerg Schwenk discovered that the SSH protocol used in FileZilla is prone to a prefix truncation attack, known as the "Terrapin attack". A remote attacker could use this issue to downgrade or disable some security features and obtain sensitive information. This update fixes the issue.
References
SRPMS
9/core
- filezilla-3.66.4-1.mga9
- libfilezilla-0.45.0-1.mga9