The code in src/sftpserver.c did not verify the validity of certain pointersand expected them to be valid. A NULL pointer dereference could have been
occurred that typically causes a crash and thus a denial-of-service
(CVE-2020-16135).
- https://bugs.mageia.org/show_bug.cgi?id=27036
- https://lists.debian.org/debian-lts-announce/2020/07/msg00034.html
- https://www.cve.org/CVERecord?id=CVE-2020-16135
- 7/core/libssh-0.8.9-1.1.mga7
Get the latest Linux and open source security news straight to your inbox.