Rebex Buru SFTP Server 2.11.2

Released: Jan 4, 2024

2.11.2 での更新項目

機能

  • Added support for strict key exchange extension (thwarts the so-called 'Terrapin attack' - CVE-2023-48795).
    • This is not a critical fix, since neither version of Buru SFTP Server relies on RFC 8308 extension negotiation mechanism, so Terrapin attack can only be used by an attacker to disrupt authentication, causing the SSH session to fail.

不具合の修正

  • Fixed 'not authenticated' instead of 'not connected' error message.
  • Allowed dates outside 1970-2999 range in SFTP v4 (or higher).