Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Slackware: 2023-354-02 critical: OpenSSL buffer overflow fix

slackware
Calendar Grey December 19, 2023
Dist Slackware Esm H88
Recent libssh improvements for Slackware tackle key protection flaws and bolster overall system security.
New libssh packages are available for Slackware 14.2, 15.0, and -current to fix security issues

Summary

Here are the details from the Slackware 15.0 ChangeLog: patches/packages/libssh-0.10.6-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: Command injection using proxycommand. Potential downgrade attack using strict kex. Missing checks for return values of MD functions. For more information, see: https://www.cve.org/CVERecord?id=CVE-2023-6004 https://www.cve.org/CVERecord?id=CVE-2023-48795 https://www.cve.org/CVERecord?id=CVE-2023-6918 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/libssh-0.10.6-i586-1_slack14.2.txz
Updated package for Slackware x86_64 14.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/libssh-0.10.6-x86_64-1_slack14.2.txz
Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libssh-0.10.6-i586-1_slack15.0.txz
Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/libssh-0.10.6-x86_64-1_slack15.0.txz
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 14.2 package: df594d833d2b61430550c4a6249e8e16 libssh-0.10.6-i586-1_slack14.2.txz
Slackware x86_64 14.2 package: 697e225933eb11593ee2db6dca0d38a8 libssh-0.10.6-x86_64-1_slack14.2.txz
Slackware 15.0 package: 122816350a43ac336e1f48fcf3c0b2aa libssh-0.10.6-i586-1_slack15.0.txz
Slackware x86_64 15.0 package: 09688c662806fcfbc8b7f2b3bf408674 libssh-0.10.6-x86_64-1_slack15.0.txz
Slackware -current package: c3a0ff73b4a2d523f99a5e06b4b8df75 l/libssh-0.10.6-i586-1.txz
Slackware x86_64 -current package: 01fba0c880daaf7536dcf31cc5553708 l/libssh-0.10.6-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg libssh-0.10.6-i586-1_slack15.0.txz

Related News

Your message here