Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Mageia 7: MGASA-2019-0402 Moderate: libssh Command Injection

mageia
Calendar Grey December 19, 2019
Dist Mageia Esm H88
Recent updates to libssh packages mitigate potential command injection vulnerabilities in Mageia 7. The issue identified as MGASA-2019-0402 targets key security vulnerabilities.
Updated libssh packages fix security vulnerability: In an environment where a user is only allowed to copy files and not to execute applications, it would be possible to pass a lo...

Summary

Updated libssh packages fix security vulnerability:
In an environment where a user is only allowed to copy files and not to execute applications, it would be possible to pass a location which contains commands to be executed in addition (CVE-2019-14889).

References

- https://bugs.mageia.org/show_bug.cgi?id=25865

- https://www.libssh.org/security/advisories/CVE-2019-14889.txt

- https://www.cve.org/CVERecord?id=CVE-2019-14889

Resolution

SRPMS

- 7/core/libssh-0.8.8-1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 19 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0402.html
Type: security
CVE: CVE-2019-14889

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here