I discovered a flaw in Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos. The backports of fixes for CVE-2022-3437 accidentally inverted important memory comparisons in the arcfour-hmac-md5 and rc4-hmac integrity check handlers for gssapi, . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3311-1
libssh2: Out-of-bounds memory comparison with specially crafted message channel request (CVE-2019-3862) SL7 x86_64 libssh2-1.4.3-12.el7_6.3.i686.rpm libssh2-1.4.3-12.el7_6.3.x86_64.rpm libssh2-debuginfo-1.4.3-12.el7_6.3.i686.rpm libssh2-debuginfo-1.4.3-12.el7_6.3.x86_64.rpm libssh2-devel-1.4.3-12.el7_6.3.i686.rpm libssh2-devel-1.4.3-12.el7_6.3.x86_64.rpm libssh2- [More...]. Synopsis: Moderate: libssh2 security update Advisory ID: SLSA-2019:1884-1 Issue Date: 2019-07-29 CVE Numbers: CVE-2019-3862 -- Security Fix(es): * libssh2: Out-of-bounds memory comparison with specially crafted message channel request (CVE-2019-3862) -- SL7 x86_64 libssh2-1.4.3-12.el7_6.3.i686.rpm libssh2-1.4.3-12.el7_6.3.x86_64.rpm libssh2-debuginfo-1.4.3-12.el7_6.3.i686.rpm libssh2-debuginfo-1.4.3-12.el7_6.3.x86_64.rpm libssh2-devel-1.4.3-12.el7_6.3.i686.rpm libssh2-devel-1.4.3-12.el7_6.3.x86_64.rpm libssh2-1.4.3-12.el7_6.3.src.rpm noarch libssh2-docs-1.4.3-12.el7_6.3.noarch.rpm - Scientific Linux Development Team . libssh2 vulnerability patch for SL7 resolves memory comparison problems associated with a specially crafted channel request. Discover further details now.. libssh2 security, memory issue, SLSA advisory, Scientific Linux update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.