[CLSA-2024:1709562050] libssh: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2024-03-04 14:20:54 UTC
Description:
- CVE-2023-6004: fix the possibility of injections through a hostname parameter in the ProxyCommand/ProxyJump features - CVE-2023-6918: fix the issue when unchecked return values for digests may cause DoS
Updated packages:
  • libssh-0.9.4-3.el8.tuxcare.els3.i686.rpm
    sha:35ec2b444684f5a0f518b33090edd489d6b9c38b
  • libssh-0.9.4-3.el8.tuxcare.els3.x86_64.rpm
    sha:413b75575c0267ac3d74f9120e9bcb75a5137c78
  • libssh-config-0.9.4-3.el8.tuxcare.els3.noarch.rpm
    sha:a3c3e325bc60bdd2531506d9eb61d1278e2f9970
  • libssh-devel-0.9.4-3.el8.tuxcare.els3.i686.rpm
    sha:70ea682e6c1cd917e93a9756c256a6129511fcc6
  • libssh-devel-0.9.4-3.el8.tuxcare.els3.x86_64.rpm
    sha:87a18420162f19289f32a68da3dff6a4ee475947
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.