Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:0130-1

Опубликовано: 20 янв. 2020
Источник: suse-cvrf

Описание

Security update for libssh

This update for libssh fixes the following issues:

  • CVE-2019-14889: Fixed an unwanted command execution in scp caused by unsanitized location (bsc#1158095).

Список пакетов

Container suse/sle15:15.0
libssh4-0.7.5-6.9.2
Image SLES15-Azure-BYOS
libssh4-0.7.5-6.9.2
Image SLES15-EC2-CHOST-HVM-BYOS
libssh4-0.7.5-6.9.2
Image SLES15-EC2-HVM-BYOS
libssh4-0.7.5-6.9.2
Image SLES15-GCE-BYOS
libssh4-0.7.5-6.9.2
Image SLES15-OCI-BYOS
libssh4-0.7.5-6.9.2
Image SLES15-SAP-Azure
libssh4-0.7.5-6.9.2
Image SLES15-SAP-Azure-BYOS
libssh4-0.7.5-6.9.2
Image SLES15-SAP-Azure-LI-BYOS-Production
libssh4-0.7.5-6.9.2
Image SLES15-SAP-Azure-VLI-BYOS-Production
libssh4-0.7.5-6.9.2
Image SLES15-SAP-EC2-HVM
libssh4-0.7.5-6.9.2
Image SLES15-SAP-EC2-HVM-BYOS
libssh4-0.7.5-6.9.2
Image SLES15-SAP-GCE
libssh4-0.7.5-6.9.2
Image SLES15-SAP-GCE-BYOS
libssh4-0.7.5-6.9.2
Image SLES15-SAP-OCI-BYOS
libssh4-0.7.5-6.9.2
SUSE Linux Enterprise High Performance Computing 15-ESPOS
libssh-devel-0.7.5-6.9.2
libssh4-0.7.5-6.9.2
libssh4-32bit-0.7.5-6.9.2
SUSE Linux Enterprise High Performance Computing 15-LTSS
libssh-devel-0.7.5-6.9.2
libssh4-0.7.5-6.9.2
libssh4-32bit-0.7.5-6.9.2
SUSE Linux Enterprise Module for Basesystem 15
libssh-devel-0.7.5-6.9.2
libssh4-0.7.5-6.9.2
libssh4-32bit-0.7.5-6.9.2
SUSE Linux Enterprise Server 15-LTSS
libssh-devel-0.7.5-6.9.2
libssh4-0.7.5-6.9.2
libssh4-32bit-0.7.5-6.9.2
SUSE Linux Enterprise Server for SAP Applications 15
libssh-devel-0.7.5-6.9.2
libssh4-0.7.5-6.9.2
libssh4-32bit-0.7.5-6.9.2

Описание

A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.


Затронутые продукты
Container suse/sle15:15.0:libssh4-0.7.5-6.9.2
Image SLES15-Azure-BYOS:libssh4-0.7.5-6.9.2
Image SLES15-EC2-CHOST-HVM-BYOS:libssh4-0.7.5-6.9.2
Image SLES15-EC2-HVM-BYOS:libssh4-0.7.5-6.9.2

Ссылки