Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Mageia: 2020-0171 Moderate: Libssh Malicious Client Crash Risk

mageia
Calendar Grey April 15, 2020
Dist Mageia Esm H88
The security notice MGASA-2020-0171 from Mageia outlines a resolution for a libssh vulnerability to mitigate potential crash threats posed by nefarious actors.

Updated libssh packages fix security vulnerability: A malicious client or server could crash the counterpart implemented with libssh AES-CTR ciphers are used and don't get fully...

Summary

Updated libssh packages fix security vulnerability:
A malicious client or server could crash the counterpart implemented with libssh AES-CTR ciphers are used and don't get fully initialized. It will crash when it tries to cleanup the AES-CTR ciphers when closing the connection (CVE-2020-1730).

References

- https://bugs.mageia.org/show_bug.cgi?id=26462

- - https://www.cve.org/CVERecord?id=CVE-2020-1730

Resolution

SRPMS

- 7/core/libssh-0.8.9-1.mga7

Publication date: 15 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0171.html
Type: security
CVE: CVE-2020-1730

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here