[SUSE-SU-2024:0140-1] Security update for libssh

Severity Important
Affected Packages 46
CVEs 5

Security update for libssh

This update for libssh fixes the following issues:

Security fixes:

  • CVE-2023-6004: Fixed command injection using proxycommand (bsc#1218209)
  • CVE-2023-48795: Fixed potential downgrade attack using strict kex (bsc#1218126)
  • CVE-2023-6918: Fixed missing checks for return values of MD functions (bsc#1218186)
  • CVE-2023-1667: Fixed NULL dereference during rekeying with algorithm guessing (bsc#1211188)
  • CVE-2023-2283: Fixed possible authorization bypass in pki_verify_data_signature under low-memory conditions (bsc#1211190)

Other fixes:

  • Update to version 0.9.8

    • Allow @ in usernames when parsing from URI composes
  • Update to version 0.9.7

    • Fix several memory leaks in GSSAPI handling code
Package Affected Version
pkg:rpm/suse/libssh4?arch=x86_64&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=x86_64&distro=slem-5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=x86_64&distro=sled-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=x86_64&distro=opensuse-leap-micro-5.4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=x86_64&distro=opensuse-leap-micro-5.3 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=x86_64&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=s390x&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=s390x&distro=slem-5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=s390x&distro=opensuse-leap-micro-5.4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=s390x&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=ppc64le&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=ppc64le&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=aarch64&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=aarch64&distro=slem-5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=aarch64&distro=opensuse-leap-micro-5.4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=aarch64&distro=opensuse-leap-micro-5.3 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4?arch=aarch64&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4-32bit?arch=x86_64&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4-32bit?arch=x86_64&distro=sled-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh4-32bit?arch=x86_64&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-devel?arch=x86_64&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-devel?arch=x86_64&distro=sled-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-devel?arch=x86_64&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-devel?arch=s390x&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-devel?arch=s390x&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-devel?arch=ppc64le&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-devel?arch=ppc64le&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-devel?arch=aarch64&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-devel?arch=aarch64&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=x86_64&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=x86_64&distro=slem-5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=x86_64&distro=sled-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=x86_64&distro=opensuse-leap-micro-5.4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=x86_64&distro=opensuse-leap-micro-5.3 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=x86_64&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=s390x&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=s390x&distro=slem-5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=s390x&distro=opensuse-leap-micro-5.4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=s390x&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=ppc64le&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=ppc64le&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=aarch64&distro=sles-15&sp=4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=aarch64&distro=slem-5 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=aarch64&distro=opensuse-leap-micro-5.4 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=aarch64&distro=opensuse-leap-micro-5.3 < 0.9.8-150400.3.3.1
pkg:rpm/suse/libssh-config?arch=aarch64&distro=opensuse-leap-15.5 < 0.9.8-150400.3.3.1
ID
SUSE-SU-2024:0140-1
Severity
important
URL
https://www.suse.com/support/update/announcement/2024/suse-su-20240140-1/
Published
2024-01-18T10:35:00
(8 months ago)
Modified
2024-01-18T10:35:00
(8 months ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/libssh4?arch=x86_64&distro=sles-15&sp=4 suse libssh4 < 0.9.8-150400.3.3.1 sles-15 x86_64
Affected pkg:rpm/suse/libssh4?arch=x86_64&distro=slem-5 suse libssh4 < 0.9.8-150400.3.3.1 slem-5 x86_64
Affected pkg:rpm/suse/libssh4?arch=x86_64&distro=sled-15&sp=4 suse libssh4 < 0.9.8-150400.3.3.1 sled-15 x86_64
Affected pkg:rpm/suse/libssh4?arch=x86_64&distro=opensuse-leap-micro-5.4 suse libssh4 < 0.9.8-150400.3.3.1 opensuse-leap-micro-5.4 x86_64
Affected pkg:rpm/suse/libssh4?arch=x86_64&distro=opensuse-leap-micro-5.3 suse libssh4 < 0.9.8-150400.3.3.1 opensuse-leap-micro-5.3 x86_64
Affected pkg:rpm/suse/libssh4?arch=x86_64&distro=opensuse-leap-15.5 suse libssh4 < 0.9.8-150400.3.3.1 opensuse-leap-15.5 x86_64
Affected pkg:rpm/suse/libssh4?arch=s390x&distro=sles-15&sp=4 suse libssh4 < 0.9.8-150400.3.3.1 sles-15 s390x
Affected pkg:rpm/suse/libssh4?arch=s390x&distro=slem-5 suse libssh4 < 0.9.8-150400.3.3.1 slem-5 s390x
Affected pkg:rpm/suse/libssh4?arch=s390x&distro=opensuse-leap-micro-5.4 suse libssh4 < 0.9.8-150400.3.3.1 opensuse-leap-micro-5.4 s390x
Affected pkg:rpm/suse/libssh4?arch=s390x&distro=opensuse-leap-15.5 suse libssh4 < 0.9.8-150400.3.3.1 opensuse-leap-15.5 s390x
Affected pkg:rpm/suse/libssh4?arch=ppc64le&distro=sles-15&sp=4 suse libssh4 < 0.9.8-150400.3.3.1 sles-15 ppc64le
Affected pkg:rpm/suse/libssh4?arch=ppc64le&distro=opensuse-leap-15.5 suse libssh4 < 0.9.8-150400.3.3.1 opensuse-leap-15.5 ppc64le
Affected pkg:rpm/suse/libssh4?arch=aarch64&distro=sles-15&sp=4 suse libssh4 < 0.9.8-150400.3.3.1 sles-15 aarch64
Affected pkg:rpm/suse/libssh4?arch=aarch64&distro=slem-5 suse libssh4 < 0.9.8-150400.3.3.1 slem-5 aarch64
Affected pkg:rpm/suse/libssh4?arch=aarch64&distro=opensuse-leap-micro-5.4 suse libssh4 < 0.9.8-150400.3.3.1 opensuse-leap-micro-5.4 aarch64
Affected pkg:rpm/suse/libssh4?arch=aarch64&distro=opensuse-leap-micro-5.3 suse libssh4 < 0.9.8-150400.3.3.1 opensuse-leap-micro-5.3 aarch64
Affected pkg:rpm/suse/libssh4?arch=aarch64&distro=opensuse-leap-15.5 suse libssh4 < 0.9.8-150400.3.3.1 opensuse-leap-15.5 aarch64
Affected pkg:rpm/suse/libssh4-32bit?arch=x86_64&distro=sles-15&sp=4 suse libssh4-32bit < 0.9.8-150400.3.3.1 sles-15 x86_64
Affected pkg:rpm/suse/libssh4-32bit?arch=x86_64&distro=sled-15&sp=4 suse libssh4-32bit < 0.9.8-150400.3.3.1 sled-15 x86_64
Affected pkg:rpm/suse/libssh4-32bit?arch=x86_64&distro=opensuse-leap-15.5 suse libssh4-32bit < 0.9.8-150400.3.3.1 opensuse-leap-15.5 x86_64
Affected pkg:rpm/suse/libssh-devel?arch=x86_64&distro=sles-15&sp=4 suse libssh-devel < 0.9.8-150400.3.3.1 sles-15 x86_64
Affected pkg:rpm/suse/libssh-devel?arch=x86_64&distro=sled-15&sp=4 suse libssh-devel < 0.9.8-150400.3.3.1 sled-15 x86_64
Affected pkg:rpm/suse/libssh-devel?arch=x86_64&distro=opensuse-leap-15.5 suse libssh-devel < 0.9.8-150400.3.3.1 opensuse-leap-15.5 x86_64
Affected pkg:rpm/suse/libssh-devel?arch=s390x&distro=sles-15&sp=4 suse libssh-devel < 0.9.8-150400.3.3.1 sles-15 s390x
Affected pkg:rpm/suse/libssh-devel?arch=s390x&distro=opensuse-leap-15.5 suse libssh-devel < 0.9.8-150400.3.3.1 opensuse-leap-15.5 s390x
Affected pkg:rpm/suse/libssh-devel?arch=ppc64le&distro=sles-15&sp=4 suse libssh-devel < 0.9.8-150400.3.3.1 sles-15 ppc64le
Affected pkg:rpm/suse/libssh-devel?arch=ppc64le&distro=opensuse-leap-15.5 suse libssh-devel < 0.9.8-150400.3.3.1 opensuse-leap-15.5 ppc64le
Affected pkg:rpm/suse/libssh-devel?arch=aarch64&distro=sles-15&sp=4 suse libssh-devel < 0.9.8-150400.3.3.1 sles-15 aarch64
Affected pkg:rpm/suse/libssh-devel?arch=aarch64&distro=opensuse-leap-15.5 suse libssh-devel < 0.9.8-150400.3.3.1 opensuse-leap-15.5 aarch64
Affected pkg:rpm/suse/libssh-config?arch=x86_64&distro=sles-15&sp=4 suse libssh-config < 0.9.8-150400.3.3.1 sles-15 x86_64
Affected pkg:rpm/suse/libssh-config?arch=x86_64&distro=slem-5 suse libssh-config < 0.9.8-150400.3.3.1 slem-5 x86_64
Affected pkg:rpm/suse/libssh-config?arch=x86_64&distro=sled-15&sp=4 suse libssh-config < 0.9.8-150400.3.3.1 sled-15 x86_64
Affected pkg:rpm/suse/libssh-config?arch=x86_64&distro=opensuse-leap-micro-5.4 suse libssh-config < 0.9.8-150400.3.3.1 opensuse-leap-micro-5.4 x86_64
Affected pkg:rpm/suse/libssh-config?arch=x86_64&distro=opensuse-leap-micro-5.3 suse libssh-config < 0.9.8-150400.3.3.1 opensuse-leap-micro-5.3 x86_64
Affected pkg:rpm/suse/libssh-config?arch=x86_64&distro=opensuse-leap-15.5 suse libssh-config < 0.9.8-150400.3.3.1 opensuse-leap-15.5 x86_64
Affected pkg:rpm/suse/libssh-config?arch=s390x&distro=sles-15&sp=4 suse libssh-config < 0.9.8-150400.3.3.1 sles-15 s390x
Affected pkg:rpm/suse/libssh-config?arch=s390x&distro=slem-5 suse libssh-config < 0.9.8-150400.3.3.1 slem-5 s390x
Affected pkg:rpm/suse/libssh-config?arch=s390x&distro=opensuse-leap-micro-5.4 suse libssh-config < 0.9.8-150400.3.3.1 opensuse-leap-micro-5.4 s390x
Affected pkg:rpm/suse/libssh-config?arch=s390x&distro=opensuse-leap-15.5 suse libssh-config < 0.9.8-150400.3.3.1 opensuse-leap-15.5 s390x
Affected pkg:rpm/suse/libssh-config?arch=ppc64le&distro=sles-15&sp=4 suse libssh-config < 0.9.8-150400.3.3.1 sles-15 ppc64le
Affected pkg:rpm/suse/libssh-config?arch=ppc64le&distro=opensuse-leap-15.5 suse libssh-config < 0.9.8-150400.3.3.1 opensuse-leap-15.5 ppc64le
Affected pkg:rpm/suse/libssh-config?arch=aarch64&distro=sles-15&sp=4 suse libssh-config < 0.9.8-150400.3.3.1 sles-15 aarch64
Affected pkg:rpm/suse/libssh-config?arch=aarch64&distro=slem-5 suse libssh-config < 0.9.8-150400.3.3.1 slem-5 aarch64
Affected pkg:rpm/suse/libssh-config?arch=aarch64&distro=opensuse-leap-micro-5.4 suse libssh-config < 0.9.8-150400.3.3.1 opensuse-leap-micro-5.4 aarch64
Affected pkg:rpm/suse/libssh-config?arch=aarch64&distro=opensuse-leap-micro-5.3 suse libssh-config < 0.9.8-150400.3.3.1 opensuse-leap-micro-5.3 aarch64
Affected pkg:rpm/suse/libssh-config?arch=aarch64&distro=opensuse-leap-15.5 suse libssh-config < 0.9.8-150400.3.3.1 opensuse-leap-15.5 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...