## This update for libssh fixes the following issues: Security fixes: * CVE-2023-6004: Fixed command injection using proxycommand (bsc#1218209) * CVE-2023-48795: Fixed potential downgrade attack using strict kex (bsc#1218126) * CVE-2023-6918: Fixed missing checks for return values of MD functions (bsc#1218186) * CVE-2023-1667: Fixed NULL dereference during rekeying with algorithm guessing (bsc#1211188) * CVE-2023-2283: Fixed possible authorization bypass in pki_verify_data_signature under low-memory conditions (bsc#1211190) Other fixes: * Update to version 0.9.8 * Allow @ in usernames when parsing from URI composes * Update to version 0.9.7 * Fix several memory leaks in GSSAPI handling code ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like
* bsc#1211188
* bsc#1211190
* bsc#1218126
* bsc#1218186
* bsc#1218209
Cross-
* CVE-2023-1667
* CVE-2023-2283
* CVE-2023-48795
* CVE-2023-6004
* CVE-2023-6918
CVSS scores:
* CVE-2023-1667 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2023-1667 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2023-2283 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2023-2283 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2023-48795 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2023-48795 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2023-6004 ( SUSE ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
* CVE-2023-6004 ( NVD ): 4.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Get the latest Linux and open source security news straight to your inbox.