[arm-allstar] Terrapin vulnerability

Patrick Perdue borrisinabox at gmail.com
Wed Dec 20 13:14:02 EST 2023


Greetings:

As some may know, a new vulnerability was discovered with SSH, both on 
the server and client end of the connection.

Here is PuTTY's write-up about this:

https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-terrapin.html

This is apparently fixed in OpenSSH servver 9.6 and PuTTY 0.80.

Just FYI for anyone who has an exposed SSH server on the internet for 
whatever reason.



More information about the ARM-allstar mailing list