ELSA-2019-0679

ELSA-2019-0679 - libssh2 security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2019-03-28

Description


[1.4.3-12.el7_6.2]
- sanitize public header file (detected by rpmdiff)

[1.4.3-12.el7_6.1]
- fix integer overflow in keyboard interactive handling that allows out-of-bounds writes (CVE-2019-3863)
- fix integer overflow in SSH packet processing channel resulting in out of bounds write (CVE-2019-3857)
- fix integer overflow in keyboard interactive handling resulting in out of bounds write (CVE-2019-3856)
- fix integer overflow in transport read resulting in out of bounds write (CVE-2019-3855)


Related CVEs


CVE-2019-3855
CVE-2019-3863
CVE-2019-3856
CVE-2019-3857

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (aarch64) libssh2-1.4.3-12.el7_6.2.src.rpm08e963b63100f7391ac344bcfe262f55ELSA-2020-3915
libssh2-1.4.3-12.el7_6.2.aarch64.rpm856e506cb40fc33e9694b8faa8201ab4ELSA-2020-3915
libssh2-devel-1.4.3-12.el7_6.2.aarch64.rpmc3e5acceb78e882d16f4770deff17063ELSA-2020-3915
libssh2-docs-1.4.3-12.el7_6.2.noarch.rpmfef2d82359b56d77a3af72cab811d6f3ELSA-2020-3915
Oracle Linux 7 (x86_64) libssh2-1.4.3-12.el7_6.2.src.rpm08e963b63100f7391ac344bcfe262f55ELSA-2020-3915
libssh2-1.4.3-12.el7_6.2.i686.rpm80b628ab77dbc1f5ec1676e5f72987dcELSA-2020-3915
libssh2-1.4.3-12.el7_6.2.x86_64.rpm6a22e8643ec3da45e90457c853adfbecELSA-2020-3915
libssh2-devel-1.4.3-12.el7_6.2.i686.rpm2005e5099755cebfd6b42b23352aa376ELSA-2020-3915
libssh2-devel-1.4.3-12.el7_6.2.x86_64.rpm563e9908cdb1ebc60f69620e3f23a678ELSA-2020-3915
libssh2-docs-1.4.3-12.el7_6.2.noarch.rpmfef2d82359b56d77a3af72cab811d6f3ELSA-2020-3915



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete