SUSE-SU-2024:0140-1
Dashboard / Vulnerabilities / SUSE-SU-2024:0140-1
SUSE-SU-2024:0140-1
Summary: Security update for libssh
Details: This update for libssh fixes the following issues: Security fixes: - CVE-2023-6004: Fixed command injection using proxycommand (bsc#1218209) - CVE-2023-48795: Fixed potential downgrade attack using strict kex (bsc#1218126) - CVE-2023-6918: Fixed missing checks for return values of MD functions (bsc#1218186) - CVE-2023-1667: Fixed NULL dereference during rekeying with algorithm guessing (bsc#1211188) - CVE-2023-2283: Fixed possible authorization bypass in pki_verify_data_signature under low-memory conditions (bsc#1211190) Other fixes: - Update to version 0.9.8 - Allow @ in usernames when parsing from URI composes - Update to version 0.9.7 - Fix several memory leaks in GSSAPI handling code
References: https://www.suse.com/support/update/announcement/2024/suse-su-20240140-1/, https://bugzilla.suse.com/1211188, https://bugzilla.suse.com/1211190, https://bugzilla.suse.com/1218126, https://bugzilla.suse.com/1218186, https://bugzilla.suse.com/1218209, https://www.suse.com/security/cve/CVE-2023-1667, https://www.suse.com/security/cve/CVE-2023-2283, https://www.suse.com/security/cve/CVE-2023-48795, https://www.suse.com/security/cve/CVE-2023-6004, https://www.suse.com/security/cve/CVE-2023-6918
Affected packages
Package
Name: libssh
Purl: pkg:rpm/suse/libssh&distro=SUSE%20Linux%20Enterprise%20Micro%205.3
Affected ranges
Type: ECOSYSTEM
Events:
