New Debian libssh2 1.7.0-1+deb9u2 fixes: This update addresses the following issues: * integer overflow in kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c leads to out-of-bounds write (CVE-2019-13115) * integer overflow in SSH_MSG_DISCONNECT logic in packet.c (CVE-2019-17498)
--- mirror/ftp/4.4/unmaintained/4.4-1/source/libssh2_1.7.0-1+deb9u1.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/libssh2_1.7.0-1+deb9u2.dsc @@ -1,3 +1,9 @@ +1.7.0-1+deb9u2 [Fri, 17 Dec 2021 20:34:06 +0100] Anton Gladky <gladk@debian.org>: + + * Non-maintainer upload by the LTS Security Team. + * CVE-2019-13115. Fix _libssh2_check_length. + * CVE-2019-17498. Fix integer overflow in packet.c. + 1.7.0-1+deb9u1 [Thu, 04 Apr 2019 23:32:50 +0200] Salvatore Bonaccorso <carnil@debian.org>: * Non-maintainer upload by the Security Team. <http://piuparts.knut.univention.de/4.4-8/#6306905588389486295>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] c49e81e344 Bug #54261: libssh2 1.7.0-1+deb9u2 doc/errata/staging/libssh2.yaml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x1129>