Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia 8: 2023-0184 Moderate: Vulnerability in Libssh NULL Dereference

mageia
Calendar Grey May 21, 2023
Dist Mageia Esm H88
Recent updates to the libssh packages in Mageia address significant security flaws, such as NULL pointer dereference and permission escalation issues.
Potential NULL dereference during rekeying with algorithm guessing

Summary

Potential NULL dereference during rekeying with algorithm guessing. (CVE-2023-1667) Authorization bypass in pki_verify_data_signature. (CVE-2023-2283

References

- https://bugs.mageia.org/show_bug.cgi?id=31925

- https://www.libssh.org/security/advisories/CVE-2023-1667.txt

- https://www.libssh.org/security/advisories/CVE-2023-2283.txt

- - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/C4KR3JZOQP2PX7KTYELHWXLPT3JRJXUM/

- https://www.cve.org/CVERecord?id=CVE-2023-1667

- https://www.cve.org/CVERecord?id=CVE-2023-2283

Resolution

SRPMS

- 8/core/libssh-0.9.7-1.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 21 May 2023
URL: https://advisories.mageia.org/MGASA-2023-0184.html
Type: security
CVE: CVE-2023-1667, CVE-2023-2283

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here