CERT-In Vulnerability Note
CIVN-2023-0387
Security Restriction Bypass Vulnerability in OpenSSL
Original Issue Date:December 26, 2023
Severity Rating: MEDIUM
Software Affected
- OpenSSL versions prior to 9.6
Overview
A vulnerability has been found in OpenSSL which may allow a remote attacker to bypass the security restrictions and perform Man-in-the-Middle attacks (MITM) on the targeted system.
Description
This vulnerability exists due to a logic error in ssh-agent(1) and improper implementation of protocol extensions within ssh(1) and ssh(8) to thwart Terrapin attacks. A remote attacker could exploit this vulnerability by passing shell metacharacters and hostnames supplied via the command-line.
Successful exploitation of this vulnerability may allow a remote attacker to bypass the security restrictions and perform Man-in-the-Middle attacks (MITM) on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.openssh.com/txt/release-9.6
Vendor Information
OpenSSH
https://www.openssh.com/txt/release-9.6
References
https://www.openssh.com/txt/release-9.6
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|