git: 09132c0a59cf - main - security/vuxml: add security/putty[-nogtk] < 0.80 'Terrapin' vulnerability

From: Matthias Andree <mandree_at_FreeBSD.org>
Date: Tue, 19 Dec 2023 22:29:47 UTC
The branch main has been updated by mandree:

URL: https://cgit.FreeBSD.org/ports/commit/?id=09132c0a59cfe3802a3d8665da42e97a0c771c94

commit 09132c0a59cfe3802a3d8665da42e97a0c771c94
Author:     Matthias Andree <mandree@FreeBSD.org>
AuthorDate: 2023-12-19 22:21:58 +0000
Commit:     Matthias Andree <mandree@FreeBSD.org>
CommitDate: 2023-12-19 22:21:58 +0000

    security/vuxml: add security/putty[-nogtk] < 0.80 'Terrapin' vulnerability
    
    Security:       91955195-9ebb-11ee-bc14-a703705db3a6
    Security:       CVE-2023-48795
---
 security/vuxml/vuln/2023.xml | 39 +++++++++++++++++++++++++++++++++++++++
 1 file changed, 39 insertions(+)

diff --git a/security/vuxml/vuln/2023.xml b/security/vuxml/vuln/2023.xml
index 420ad875bb46..e4f49f5c61c6 100644
--- a/security/vuxml/vuln/2023.xml
+++ b/security/vuxml/vuln/2023.xml
@@ -1,3 +1,42 @@
+  <vuln vid="91955195-9ebb-11ee-bc14-a703705db3a6">
+    <topic>putty -- add protocol extension against 'Terrapin attack'</topic>
+    <affects>
+      <package>
+	<name>putty</name>
+	<range><lt>0.80</lt></range>
+      </package>
+       <package>
+	<name>putty-nogtk</name>
+	<range><lt>0.80</lt></range>
+      </package>
+    </affects>
+    <description>
+	<body xmlns="http://www.w3.org/1999/xhtml">
+	<p>Simon Tatham reports:</p>
+	<blockquote cite="https://lists.tartarus.org/pipermail/putty-announce/2023/000037.html">
+		<p>PuTTY version 0.80 [contains] one security fix [...] for a newly discovered security issue known as the 'Terrapin'
+   attack, also numbered CVE-2023-48795. The issue affects widely-used
+   OpenSSH extensions to the SSH protocol: the ChaCha20+Poly1305
+   cipher system, and 'encrypt-then-MAC' mode.</p>
+   <p>In order to benefit from the fix, you must be using a fixed version
+   of PuTTY _and_ a server with the fix, so that they can agree to
+	   adopt a modified version of the protocol. [...]</p>
+	</blockquote>
+	</body>
+    </description>
+    <references>
+      <cvename>CVE-2023-48795</cvename>
+      <url>https://lists.tartarus.org/pipermail/putty-announce/2023/000037.html</url>
+      <url>https://www.openssh.com/txt/release-9.6</url>
+      <url>https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html</url>
+      <url>https://terrapin-attack.com/</url>
+    </references>
+    <dates>
+      <discovery>2023-10-16</discovery>
+      <entry>2023-12-19</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="76c2110b-9e97-11ee-ae23-a0f3c100ae18">
     <topic>slurm-wlm -- Several security issues</topic>
     <affects>