ELSA-2019-2136

ELSA-2019-2136 - libssh2 security, bug fix, and enhancement update

Type:SECURITY
Impact:MODERATE
Release Date:2019-08-13

Description


[1.8.0-3]
- sanitize public header file (detected by rpmdiff)

[1.8.0-2]
- fix integer overflow in keyboard interactive handling that allows out-of-bounds writes (CVE-2019-3863)
- fix out-of-bounds memory comparison with specially crafted message channel request (CVE-2019-3862)
- fix out-of-bounds reads with specially crafted SSH packets (CVE-2019-3861)
- fix zero-byte allocation in SFTP packet processing resulting in out-of-bounds read (CVE-2019-3858)
- fix integer overflow in SSH packet processing channel resulting in out of bounds write (CVE-2019-3857)
- fix integer overflow in keyboard interactive handling resulting in out of bounds write (CVE-2019-3856)
- fix integer overflow in transport read resulting in out of bounds write (CVE-2019-3855)

[1.8.0-1]
- rebase to 1.8.0 (#1592784)


Related CVEs


CVE-2019-3861
CVE-2019-3858

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (aarch64) libssh2-1.8.0-3.el7.src.rpm4c6ccf17d4a6901500e52c444e86c1d7662ea989ade90f80adf27766d8ebb2caELSA-2023-5615ol7_aarch64_latest
libssh2-1.8.0-3.el7.src.rpm4c6ccf17d4a6901500e52c444e86c1d7662ea989ade90f80adf27766d8ebb2caELSA-2023-5615ol7_aarch64_u7_base
libssh2-1.8.0-3.el7.src.rpm4c6ccf17d4a6901500e52c444e86c1d7662ea989ade90f80adf27766d8ebb2caELSA-2023-5615ol7_aarch64_u8_base
libssh2-1.8.0-3.el7.aarch64.rpmad1afba3f76e1ad055d3010ddfb5ad255f42f61e10730ce6eec316b22728fd83ELSA-2023-5615ol7_aarch64_latest
libssh2-1.8.0-3.el7.aarch64.rpmad1afba3f76e1ad055d3010ddfb5ad255f42f61e10730ce6eec316b22728fd83ELSA-2023-5615ol7_aarch64_u7_base
libssh2-1.8.0-3.el7.aarch64.rpmad1afba3f76e1ad055d3010ddfb5ad255f42f61e10730ce6eec316b22728fd83ELSA-2023-5615ol7_aarch64_u8_base
libssh2-devel-1.8.0-3.el7.aarch64.rpm96bba8c027349a4d6ba0d55c2bef57149c450348dd2042058afb65968b4a4774ELSA-2023-5615ol7_aarch64_optional_latest
libssh2-docs-1.8.0-3.el7.noarch.rpmbeb3b6640952916e3e6b52272f30df405b42c87c2f95fffd005db79a2c638189ELSA-2023-5615ol7_aarch64_optional_latest
Oracle Linux 7 (x86_64) libssh2-1.8.0-3.el7.src.rpm4c6ccf17d4a6901500e52c444e86c1d7662ea989ade90f80adf27766d8ebb2caELSA-2023-5615ol7_x86_64_latest
libssh2-1.8.0-3.el7.src.rpm4c6ccf17d4a6901500e52c444e86c1d7662ea989ade90f80adf27766d8ebb2caELSA-2023-5615ol7_x86_64_u7_base
libssh2-1.8.0-3.el7.src.rpm4c6ccf17d4a6901500e52c444e86c1d7662ea989ade90f80adf27766d8ebb2caELSA-2023-5615ol7_x86_64_u8_base
libssh2-1.8.0-3.el7.i686.rpmb4a1f036d6f6350e528c4d1edc236b3abb328e5b59bffd415716897e400cf775ELSA-2023-5615ol7_x86_64_latest
libssh2-1.8.0-3.el7.i686.rpmb4a1f036d6f6350e528c4d1edc236b3abb328e5b59bffd415716897e400cf775ELSA-2023-5615ol7_x86_64_u7_base
libssh2-1.8.0-3.el7.i686.rpmb4a1f036d6f6350e528c4d1edc236b3abb328e5b59bffd415716897e400cf775ELSA-2023-5615ol7_x86_64_u8_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.2.10.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.2.11.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.2.12.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.2.13.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.2.14.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.2.15.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.2.16.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.2.17.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.2.18.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.2.19.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.2.8.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.2.9.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.0.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.1.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.10.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.11.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.12.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.13.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.2.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.3.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.4.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.5.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.6.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.7.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.8.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_19.3.9.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_20.1.0.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_20.1.1.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_20.1.2.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615exadata_dbserver_20.1.3.0.0_x86_64_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615ol7_x86_64_latest
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615ol7_x86_64_u7_base
libssh2-1.8.0-3.el7.x86_64.rpm662354033eb2719efcc897e89847a9023538c6d2e9a8c14825b7f9630e7aab08ELSA-2023-5615ol7_x86_64_u8_base
libssh2-devel-1.8.0-3.el7.i686.rpm03673319af027c384403bfcd6f98d96f0176f4ae421015cd8bf5b42dcebd2eb2ELSA-2023-5615ol7_x86_64_optional_latest
libssh2-devel-1.8.0-3.el7.x86_64.rpm0bd6c86620ceb2dbeb8973b34e37388f396aaebad5a6359362b30cfd9d90a60eELSA-2023-5615ol7_x86_64_optional_latest
libssh2-docs-1.8.0-3.el7.noarch.rpmbeb3b6640952916e3e6b52272f30df405b42c87c2f95fffd005db79a2c638189ELSA-2023-5615ol7_x86_64_optional_latest



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete