ELSA-2015-2140

ELSA-2015-2140 - libssh2 security and bug fix update

Type:SECURITY
Severity:LOW
Release Date:2015-11-23

Description


[1.4.3-10]
- check length of data extracted from the SSH_MSG_KEXINIT packet (CVE-2015-1782)

[1.4.3-9]
- curl consumes too much memory during scp download (#1080459)
- prevent a not-connected agent from closing STDIN (#1147717)


Related CVEs


CVE-2015-1782

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (x86_64) libssh2-1.4.3-10.el7.src.rpm554aebda6f9156b841c0a8c79954b873ELSA-2020-3915
libssh2-1.4.3-10.el7.i686.rpm28782e5d3798d65098bd208b94881e61ELSA-2020-3915
libssh2-1.4.3-10.el7.x86_64.rpm8d2be032eefced20bd2977f7978eeea9ELSA-2020-3915
libssh2-devel-1.4.3-10.el7.i686.rpm90c8604d08a2377710c79ebb71fb6a02ELSA-2020-3915
libssh2-devel-1.4.3-10.el7.x86_64.rpmbf31e4693b83e995fd325926d22a0727ELSA-2020-3915
libssh2-docs-1.4.3-10.el7.noarch.rpmc952cdec4947f6bcc5a6280add9f959fELSA-2020-3915



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete