Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian LTS: DLA-2038-1 Critical Libssh Update With Arbitrary Command Risk

debian lts
Calendar Grey December 17, 2019
Dist Debian Esm H88
Update libssh library version to 0.6.3-4+deb8u4 to address significant input validation vulnerability that permits arbitrary command execution.
It was found that libssh, a tiny C SSH library, does not sufficiently sanitize path parameters provided to the server, allowing an attacker with only SCP file access to execute arb...

Summary

We recommend that you upgrade your libssh packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: libssh
Version: 0.6.3-4+deb8u4
CVE ID: CVE-2019-14889
Debian Bug: 946548

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here