Advisories ยป MGASA-2024-0034

Updated filezilla packages fix a security vulnerability ("Terrapin attack")

Publication date: 10 Feb 2024
Modification date: 10 Feb 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-48795

Description

Fabian Baeumer, Marcus Brinkmann and Joerg Schwenk discovered that the
SSH protocol used in FileZilla is prone to a prefix truncation attack,
known as the "Terrapin attack". A remote attacker could use this issue
to downgrade or disable some security features and obtain sensitive
information.
This update fixes the issue.
                

References

SRPMS

9/core