Описание
Security update for libssh
This update for libssh fixes the following issues:
- CVE-2025-5318: Fixed likely read beyond bounds in sftp server handle management (bsc#1245311).
- CVE-2025-4877: Fixed write beyond bounds in binary to base64 conversion functions (bsc#1245309).
- CVE-2025-4878: Fixed use of uninitialized variable in privatekey_from_file() (bsc#1245310).
- CVE-2025-5372: Fixed cases where ssh_kdf() returns a success code on certain failures (bsc#1245314).
Список пакетов
Container bci/bci-sle15-kernel-module-devel:15.6
Container bci/bci-sle15-kernel-module-devel:latest
Container bci/gcc:latest
Container bci/golang:1.23
Container bci/golang:1.23-openssl
Container bci/golang:latest
Container bci/kiwi:latest
Container bci/node:20
Container bci/nodejs:latest
Container bci/openjdk:17
Container bci/openjdk:latest
Container bci/php-apache:latest
Container bci/php-fpm:latest
Container bci/php:latest
Container bci/python:3
Container bci/python:latest
Container bci/ruby:2
Container bci/ruby:latest
Container bci/rust:1.86
Container bci/rust:latest
Container bci/spack:0.23
Container bci/spack:latest
Container containers/open-webui-pipelines:0
Container containers/open-webui:0
Container containers/pytorch:2-nvidia
Container suse/git:latest
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
Container suse/kiosk/firefox-esr:latest
Container suse/sle15:15.6
Container suse/sle15:latest
SUSE Linux Enterprise Module for Basesystem 15 SP6
SUSE Linux Enterprise Module for Basesystem 15 SP7
openSUSE Leap 15.6
Ссылки
- Link for SUSE-SU-2025:02229-1
- E-Mail link for SUSE-SU-2025:02229-1
- SUSE Security Ratings
- SUSE Bug 1245309
- SUSE Bug 1245310
- SUSE Bug 1245311
- SUSE Bug 1245314
- SUSE CVE CVE-2025-4877 page
- SUSE CVE CVE-2025-4878 page
- SUSE CVE CVE-2025-5318 page
- SUSE CVE CVE-2025-5372 page
Описание
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Затронутые продукты
Ссылки
- CVE-2025-4877
- SUSE Bug 1245309
Описание
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Затронутые продукты
Ссылки
- CVE-2025-4878
- SUSE Bug 1245310
Описание
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Затронутые продукты
Ссылки
- CVE-2025-5318
- SUSE Bug 1245311
Описание
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Затронутые продукты
Ссылки
- CVE-2025-5372
- SUSE Bug 1245314