From nobody Tue Dec 19 22:29:47 2023 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4SvrwX6jq4z558wZ; Tue, 19 Dec 2023 22:29:48 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4SvrwX08Klz4Sfn; Tue, 19 Dec 2023 22:29:48 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1703024988; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=B1H62MZR+FTts+9Vqe+9kfS2EkqtDgaJ5dAUDUv5Gzc=; b=gUOYV3+TikKpp/VTMd9Ql0uXwlDotC68f9GSP99yZDX4tXwWlDgcKZ2IpPegFgnCQRDpei qOpjFTR8B0uN4LDW6ROd+Div0Qnz9ayLkLW+owLVLKxiCLp6t8SehWA+b4LUhycrDzeA3g NYpges3tviTvPmUWxL9cNQtPVpf3bCk0b/fx0S18kCGAKuE/FQL0Dgg4OfIguTIZumGLoA SpJtoS5fsxJg/6qxgVcJGPvXVkTiYLnYSe4y1Y1cwih9wnDEVZ8gC+t4WuC3qNvG/qXlS4 54fBivkQ8KLXFsvzauutBB4VydPp2EOeprRrwYYTcgbmHvItjIIhI4e+gveyxQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1703024988; a=rsa-sha256; cv=none; b=ofybF34BwihoW0jcjjbhrWZyUbrWVXktIjDFLflknd+RqbdnLlOQyk80T1/VmxnPn9CXQ7 ep/bQ4gxjRSLp0ck0G/k/0oj6Z4O0ix2SyaXvT6/vNU6CZGNhBzlLHX6XPF1G4Oqh5LLyW CBPJBuQIBD0r8JKVZTy7TETa1kO1guUzITS6lBh54R6YMG5x0A6C55wOz+F/oC32r2+vIq hqCTLlDagw7d5INlDmJEiBMenSqx3Sh1zKVOlZ373ls0HJZum1g1EbzIjFDJnC2ZClYsGH sbBhdKGqC0QDsX0+ca0AT3qUjGxJcME01AZoKjNIfkcAlrNW2RfGyYubdaph6A== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1703024988; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=B1H62MZR+FTts+9Vqe+9kfS2EkqtDgaJ5dAUDUv5Gzc=; b=gbv+7LLfLVfKkdWzd+TtufQOUBVScxeSvh/jENhbxdruegTcq2LLNDptF10QY2Ml2PbjcD NRfTlSEQ8bbS93nxOYAjgr1tRVY3c9su6UwsZqqUXRqMMp4yscP9KievjJXAnR8nU61r6h VQ2QKam7jS08C5W1hxD/DnB23WWUFlMHOdzkKV4IkV+iVpkh+lA2crC8ME3QjwcYgQoDPr s+k1djciWboLKIlEwJSTI5ZCezFrfLugxgm2sFgLiDDChpeKJCcBYOyfP8CQILAkjLd734 VG2RWSuPDeYrgeJ3VHoTT9cM6b/+DnPdLIqk1InqQ9dQU1JDW/i4V1rzDO0fww== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4SvrwW5Y2Lz80v; Tue, 19 Dec 2023 22:29:47 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 3BJMTlsm018633; Tue, 19 Dec 2023 22:29:47 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 3BJMTlpN018630; Tue, 19 Dec 2023 22:29:47 GMT (envelope-from git) Date: Tue, 19 Dec 2023 22:29:47 GMT Message-Id: <202312192229.3BJMTlpN018630@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Matthias Andree Subject: git: 09132c0a59cf - main - security/vuxml: add security/putty[-nogtk] < 0.80 'Terrapin' vulnerability List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-main@freebsd.org X-BeenThere: dev-commits-ports-main@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: mandree X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 09132c0a59cfe3802a3d8665da42e97a0c771c94 Auto-Submitted: auto-generated The branch main has been updated by mandree: URL: https://cgit.FreeBSD.org/ports/commit/?id=09132c0a59cfe3802a3d8665da42e97a0c771c94 commit 09132c0a59cfe3802a3d8665da42e97a0c771c94 Author: Matthias Andree AuthorDate: 2023-12-19 22:21:58 +0000 Commit: Matthias Andree CommitDate: 2023-12-19 22:21:58 +0000 security/vuxml: add security/putty[-nogtk] < 0.80 'Terrapin' vulnerability Security: 91955195-9ebb-11ee-bc14-a703705db3a6 Security: CVE-2023-48795 --- security/vuxml/vuln/2023.xml | 39 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 39 insertions(+) diff --git a/security/vuxml/vuln/2023.xml b/security/vuxml/vuln/2023.xml index 420ad875bb46..e4f49f5c61c6 100644 --- a/security/vuxml/vuln/2023.xml +++ b/security/vuxml/vuln/2023.xml @@ -1,3 +1,42 @@ + + putty -- add protocol extension against 'Terrapin attack' + + + putty + 0.80 + + + putty-nogtk + 0.80 + + + + +

Simon Tatham reports:

+
+

PuTTY version 0.80 [contains] one security fix [...] for a newly discovered security issue known as the 'Terrapin' + attack, also numbered CVE-2023-48795. The issue affects widely-used + OpenSSH extensions to the SSH protocol: the ChaCha20+Poly1305 + cipher system, and 'encrypt-then-MAC' mode.

+

In order to benefit from the fix, you must be using a fixed version + of PuTTY _and_ a server with the fix, so that they can agree to + adopt a modified version of the protocol. [...]

+
+ +
+ + CVE-2023-48795 + https://lists.tartarus.org/pipermail/putty-announce/2023/000037.html + https://www.openssh.com/txt/release-9.6 + https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html + https://terrapin-attack.com/ + + + 2023-10-16 + 2023-12-19 + +
+ slurm-wlm -- Several security issues