Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-4545

Опубликовано: 10 нояб. 2020
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2020-4545: libssh security, bug fix, and enhancement update (MODERATE)

[0.9.4-2]

  • Do not return error when server properly closed the channel (#1849071)
  • Add a test for CVE-2019-14889
  • Do not parse configuration file in torture_knownhosts test

[0.9.4-1]

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

libssh

0.9.4-2.el8

libssh-config

0.9.4-2.el8

libssh-devel

0.9.4-2.el8

Oracle Linux x86_64

libssh

0.9.4-2.el8

libssh-config

0.9.4-2.el8

libssh-devel

0.9.4-2.el8

Связанные CVE

Связанные уязвимости

rocky
около 5 лет назад

Moderate: libssh security, bug fix, and enhancement update

suse-cvrf
почти 2 года назад

Security update for libssh

suse-cvrf
почти 2 года назад

Security update for libssh

CVSS3: 5.3
ubuntu
больше 5 лет назад

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.

CVSS3: 5.3
redhat
больше 5 лет назад

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.