[SUSE-SU-2024:0543-1] Security update for libssh2_org

Severity Important
Affected Packages 6
CVEs 1

Security update for libssh2_org

This update for libssh2_org fixes the following issues:

  • Always add the KEX pseudo-methods 'ext-info-c' and 'kex-strict-c-v00@openssh.com'
    when configuring custom method list. [bsc#1218971, CVE-2023-48795]

    • The strict-kex extension is announced in the list of available KEX methods. However, when the default KEX method list is modified or replaced, the extension is not added back automatically.
ID
SUSE-SU-2024:0543-1
Severity
important
URL
https://www.suse.com/support/update/announcement/2024/suse-su-20240543-1/
Published
2024-02-20T15:04:50
(6 months ago)
Modified
2024-02-20T15:04:50
(6 months ago)
Rights
Copyright 2024 SUSE LLC. All rights reserved.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/libssh2-1?arch=x86_64&distro=sles-12&sp=5 suse libssh2-1 < 1.11.0-29.12.1 sles-12 x86_64
Affected pkg:rpm/suse/libssh2-1?arch=s390x&distro=sles-12&sp=5 suse libssh2-1 < 1.11.0-29.12.1 sles-12 s390x
Affected pkg:rpm/suse/libssh2-1?arch=ppc64le&distro=sles-12&sp=5 suse libssh2-1 < 1.11.0-29.12.1 sles-12 ppc64le
Affected pkg:rpm/suse/libssh2-1?arch=aarch64&distro=sles-12&sp=5 suse libssh2-1 < 1.11.0-29.12.1 sles-12 aarch64
Affected pkg:rpm/suse/libssh2-1-32bit?arch=x86_64&distro=sles-12&sp=5 suse libssh2-1-32bit < 1.11.0-29.12.1 sles-12 x86_64
Affected pkg:rpm/suse/libssh2-1-32bit?arch=s390x&distro=sles-12&sp=5 suse libssh2-1-32bit < 1.11.0-29.12.1 sles-12 s390x
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...