[CLSA-2024:1711475067] libssh: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2024-03-26 18:03:38 UTC
Description:
- CVE-2023-1667: fix possible NULL-pointer dereference during re-keying with algorithm guessing - CVE-2023-48795: fix the prefix truncation attack on Binary Packet Protocol
Updated packages:
  • libssh-0.10.4-8.el9.tuxcare.els2.i686.rpm
    sha:1aef6e0f2184876b20b35018cd1372e4e2dde09b
  • libssh-0.10.4-8.el9.tuxcare.els2.x86_64.rpm
    sha:c22c066195214dbffbda227b57d88083f8a2e80a
  • libssh-config-0.10.4-8.el9.tuxcare.els2.noarch.rpm
    sha:446858f43daa6429a6b9bdf8104611f712dc46bc
  • libssh-devel-0.10.4-8.el9.tuxcare.els2.i686.rpm
    sha:94d57a99a2a21923dd31e3b98d7f3b91cb88987b
  • libssh-devel-0.10.4-8.el9.tuxcare.els2.x86_64.rpm
    sha:b2aeb561f111611df426505affd909d4b428e590
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.