Security update for tinyssh
This update for tinyssh fixes the following issues: tinyssh was updated to 20240101 (boo#1218197, CVE-2023-48795): * fixed channel_forkpty() race condition between close(slave) in parent process and login_tty(slave) in child process * fixed behavior when using terminal mode and stdin redirected to /dev/null 'ssh -tt -n' * added an 'strict-key' key exchange kex-strict- [email protected] (Mitigates CVE-2023-48795 'Terrapin attack')
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for tinyssh fixes the following issues: tinyssh was updated to 20240101 (boo#1218197, CVE-2023-48795): * fixed channel_forkpty() race condition between close(slave) in parent process and login_tty(slave) in child process * fixed behavior when using terminal mode and stdin redirected to /dev/null 'ssh -tt -n' * added an 'strict-key' key exchange kex-strict- [email protected] (Mitigates CVE-2023-48795 'Terrapin attack')
05 / REFERENCES