Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian LTS DLA-1991-1: Libssh2 Critical Integer Overflow Risk

debian lts
Calendar Grey November 13, 2019
Dist Debian Esm H88
A buffer overflow flaw in OpenSSL could lead to unauthorized access or system crashes in server installations.
In libssh2, SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent mem...

Summary

For Debian 8 "Jessie", this problem has been fixed in version
1.4.3-4.1+deb8u6.

We recommend that you upgrade your libssh2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: libssh2
Version: 1.4.3-4.1+deb8u6
CVE ID: CVE-2019-17498
Debian Bug: 943562

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here