MGASA-2015-0209
Dashboard / Vulnerabilities / MGASA-2015-0209
Summary: Updated libssh packages fix CVE-2015-3146
Details: Updated libssh packages fix security vulnerability: libssh versions 0.5.1 and above, but before 0.6.5, have a logical error in the handling of a SSH_MSG_NEWKEYS and SSH_MSG_KEXDH_REPLY package. A detected error did not set the session into the error state correctly and further processed the packet which leads to a null pointer dereference. This is the packet after the initial key exchange and doesn't require authentication. This could be used for a Denial of Service (DoS) attack (CVE-2015-3146).
References: https://advisories.mageia.org/MGASA-2015-0209.html, https://bugs.mageia.org/show_bug.cgi?id=15861, https://www.libssh.org/2015/04/30/libssh-0-6-5-security-and-bugfix-release/
Affected packages
Package
Name: libssh
Purl: pkg:rpm/mageia/libssh?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
