Debian LTS: DLA-3899-1: python-asyncssh Security Advisory Updates
Summary
CVE-2023-46445
A vulnerability has been discovered that allows attackers to control
the extension info message (RFC 8308) via a man-in-the-middle attack
(aka Rogue Extension Negotiation).
CVE-2023-46446
A vulnerability has been discovered that allows attackers to control
the remote end of an SSH client session via packet injection/removal
and shell emulation (aka Rogue Session attack).
CVE-2023-48795
A vulnerability has been discovered allows remote attackers to bypass
integrity checks, and a client and server may consequently end up with
a connection for which some security features have been downgraded or
disabled (aka Terrapin attack).
For Debian 11 bullseye, these problems have been fixed in version
2.5.0-0.1+deb11u1.
We recommend that you upgrade your python-asyncssh packages.
For the detailed security status of python-asyncssh please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-asyncssh
Further information about...