[CLSA-2024:1709547699] libssh: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2024-03-04 10:21:43 UTC
Description:
- CVE-2023-6004: fix the possibility of injections through a hostname parameter in the ProxyCommand/ProxyJump features - CVE-2023-6918: fix the issue when unchecked return values for digests may cause DoS
Updated packages:
  • libssh-0.10.4-8.el9.tuxcare.els1.i686.rpm
    sha:d2855798af0d23f0d3afbf2c395db99a318cb175
  • libssh-0.10.4-8.el9.tuxcare.els1.x86_64.rpm
    sha:37082e2424a730ae7e81fd868436e8e05966e24c
  • libssh-config-0.10.4-8.el9.tuxcare.els1.noarch.rpm
    sha:2055a39f717bb1d89c34de2973f4f394fb6fd82e
  • libssh-devel-0.10.4-8.el9.tuxcare.els1.i686.rpm
    sha:9f0e6dda269d69d2efa19d9f18fb876f77fb13ec
  • libssh-devel-0.10.4-8.el9.tuxcare.els1.x86_64.rpm
    sha:62b19a5e56197559ef4895a3519e37f89e442cd4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.