Lucene search

K
ubuntuUbuntuUSN-6589-1
HistoryJan 18, 2024 - 12:00 a.m.

FileZilla vulnerability

2024-01-1800:00:00
ubuntu.com
16
filezilla
terrapin attack
ssh protocol
prefix truncation
remote attacker
security features
sensitive information
ubuntu
vulnerability

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

6.7 Medium

AI Score

Confidence

High

0.963 High

EPSS

Percentile

99.5%

Releases

  • Ubuntu 23.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages

  • filezilla - Full-featured graphical FTP/FTPS/SFTP client

Details

Fabian Baeumer, Marcus Brinkmann and Joerg Schwenk discovered that the SSH
protocol used in FileZilla is prone to a prefix truncation attack, known as
the “Terrapin attack”. A remote attacker could use this issue to downgrade or
disable some security features and obtain sensitive information.

5.9 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

6.7 Medium

AI Score

Confidence

High

0.963 High

EPSS

Percentile

99.5%