[ELSA-2020-4545] libssh security, bug fix, and enhancement update

Severity Moderate
Affected Packages 3
CVEs 2

[0.9.4-2]
- Do not return error when server properly closed the channel (#1849071)
- Add a test for CVE-2019-14889
- Do not parse configuration file in torture_knownhosts test

[0.9.4-1]
- Update to version 0.9.4
https://www.libssh.org/2020/04/09/libssh-0-9-4-and-libssh-0-8-9-security-release/
- Fixed CVE-2019-14889 (#1781782)
- Fixed CVE-2020-1730 (#1802422)
- Create missing directories in the path provided for known_hosts files (#1733914)
- Removed inclusion of OpenSSH server configuration file from
libssh_server.config (#1821339)

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/libssh?distro=oraclelinux-8 oraclelinux libssh < 0.9.4-2.el8 oraclelinux-8
Affected pkg:rpm/oraclelinux/libssh-devel?distro=oraclelinux-8 oraclelinux libssh-devel < 0.9.4-2.el8 oraclelinux-8
Affected pkg:rpm/oraclelinux/libssh-config?distro=oraclelinux-8 oraclelinux libssh-config < 0.9.4-2.el8 oraclelinux-8
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...