Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Ubuntu 21.04 & 20.04 LTS USN-5053-1 Severe Denial of Service

Ubuntu Large Esm H500
libssh could be made to crash or run programs if it received specially crafted network traffic.
=========================================================================Ubuntu Security Notice USN-5053-1
August 26, 2021

libssh vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.04
- Ubuntu 20.04 LTS

Summary:

libssh could be made to crash or run programs if it received specially
crafted network traffic.

Software Description:
- libssh: A tiny C SSH library

Details:

It was discovered that libssh incorrectly handled rekeying. A remote
attacker could use this issue to cause libssh to crash, resulting in a
denial of service, or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.04:
  libssh-4                        0.9.5-1ubuntu0.1

Ubuntu 20.04 LTS:
  libssh-4                        0.9.3-2ubuntu2.2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5053-1
  CVE-2021-3634

Package Information:
  https://launchpad.net/ubuntu/+source/libssh/0.9.5-1ubuntu0.1
  https://launchpad.net/ubuntu/+source/libssh/0.9.3-2ubuntu2.2

Ubuntu 21.04 & 20.04 LTS USN-5053-1 Severe Denial of Service

ubuntu
Calendar Grey August 26, 2021
Dist Ubuntu Esm H88
A vulnerability in libssh can lead to system crashes or arbitrary code execution from manipulated input. Update your Ubuntu 20.04 LTS and 21.04 installations promptly to fix this
libssh could be made to crash or run programs if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: libssh-4 0.9.5-1ubuntu0.1 Ubuntu 20.04 LTS: libssh-4 0.9.3-2ubuntu2.2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5053-1

CVE-2021-3634

Severity
critical
Lowest
Low
Medium
High
Critical

August 26, 2021

Package Information

https://launchpad.net/ubuntu/+source/libssh/0.9.5-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libssh/0.9.3-2ubuntu2.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here