OpenSSH Vulnerability Security Update Advisory (CVE-2023-48795)

Overview

An update has been made available to fix vulnerabilities in OpenSSH(https://www.openssh.com/). Users of affected products are advised to update to the latest version.

 

Affected Products

OpenSSH versions earlier than 9.6

 

Resolved Vulnerabilities

Terrapin attack exploiting a flaw in the initial key exchange phase of OpenSSH (CVE-2023-48795)

 

Vulnerability Patches

Please follow the security advisory published on December 28, 2023 to update to the applicable version and the latest version.

OpenSSH 9.6 version

 

Referenced Sites

[1] https://www.openssh.com/security.html

[2] https://www.openssh.com/txt/release-9.6

[3] https://ofbiz.apache.org/download.html