Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Ubuntu 20.04 USN-4001-1 High: OpenSSL Vulnerability in Certificate Handling

Ubuntu Large Esm H500
libssh could allow unintended access to network services.
=========================================================================Ubuntu Security Notice USN-3795-2
October 22, 2018

libssh vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.10

Summary:

libssh could allow unintended access to network services.

Software Description:
- libssh: A tiny C SSH library

Details:

USN-3795-1 fixed a vulnerability in libssh. This update provides the
corresponding update for Ubuntu 18.10.

Original advisory details:

 Peter Winter-Smith discovered that libssh incorrectly handled
 authentication when being used as a server. A remote attacker could use
 this issue to bypass authentication without any credentials.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
  libssh-4                        0.8.1-1ubuntu0.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  
  https://ubuntu.com/security/notices/USN-3795-1
  CVE-2018-10933

Package Information:
  https://launchpad.net/ubuntu/+source/libssh/0.8.1-1ubuntu0.1

Ubuntu 20.04 USN-4001-1 High: OpenSSL Vulnerability in Certificate Handling

ubuntu
Calendar Grey October 22, 2018
Dist Ubuntu Esm H88
A vulnerability in libssh found in Ubuntu may enable unauthorized access to network services, as noted in Security Notice USN-3795-2.
libssh could allow unintended access to network services.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10: libssh-4 0.8.1-1ubuntu0.1 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3795-1

CVE-2018-10933

Severity
important
Lowest
Low
Medium
High
Critical

October 22, 2018

Package Information

https://launchpad.net/ubuntu/+source/libssh/0.8.1-1ubuntu0.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here