Moderate: libssh2 security update
Date: Thu, 10 Mar 2016 18:46:45 -0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
From: Pat Riehecky
Subject: Security ERRATA Moderate: libssh2 on SL6.x, SL7.x i386/x86_64
MIME-Version: 1.0
Message-ID: <20160310184645.10987.51763@slpackages.fnal.gov>
Synopsis: Moderate: libssh2 security update
Advisory ID: SLSA-2016:0428-1
Issue Date: 2016-03-10
CVE Numbers: CVE-2016-0787
--
A type confusion issue was found in the way libssh2 generated ephemeral
secrets for the diffie-hellman-group1 and diffie-hellman-group14 key
exchange methods. This would cause an SSHv2 Diffie-Hellman handshake to
use significantly less secure random parameters. (CVE-2016-0787)
After installing these updated packages, all running applications using
libssh2 must be restarted for this update to take effect.
--
SL6
x86_64
libssh2-1.4.2-2.el6_7.1.i686.rpm
libssh2-1.4.2-2.el6_7.1.x86_64.rpm
libssh2-debuginfo-1.4.2-2.el6_7.1.i686.rpm
libssh2-debuginfo-1.4.2-2.el6_7.1.x86_64.rpm
libssh2-devel-1.4.2-2.el6_7.1.i686.rpm
libssh2-devel-1.4.2-2.el6_7.1.x86_64.rpm
libssh2-docs-1.4.2-2.el6_7.1.x86_64.rpm
i386
libssh2-1.4.2-2.el6_7.1.i686.rpm
libssh2-debuginfo-1.4.2-2.el6_7.1.i686.rpm
libssh2-devel-1.4.2-2.el6_7.1.i686.rpm
libssh2-docs-1.4.2-2.el6_7.1.i686.rpm
SL7
x86_64
libssh2-1.4.3-10.el7_2.1.i686.rpm
libssh2-1.4.3-10.el7_2.1.x86_64.rpm
libssh2-debuginfo-1.4.3-10.el7_2.1.i686.rpm
libssh2-debuginfo-1.4.3-10.el7_2.1.x86_64.rpm
libssh2-devel-1.4.3-10.el7_2.1.i686.rpm
libssh2-devel-1.4.3-10.el7_2.1.x86_64.rpm
noarch
libssh2-docs-1.4.3-10.el7_2.1.noarch.rpm
- Scientific Linux Development Team