FS#70009 - [libssh2] [Security] information disclosure (CVE-2019-17498)
Attached to Project:
Arch Linux
Opened by Remi Gacogne (rgacogne) - Tuesday, 16 March 2021, 08:57 GMT
Last edited by Felix Yan (felixonmars) - Friday, 19 March 2021, 14:31 GMT
Opened by Remi Gacogne (rgacogne) - Tuesday, 16 March 2021, 08:57 GMT
Last edited by Felix Yan (felixonmars) - Friday, 19 March 2021, 14:31 GMT
|
Details
Summary
======= The package libssh2 is vulnerable to information disclosure via CVE-2019-17498. Guidance ======== A patch to the PKGBUILD applying the official patch is attached to this report. References ========== https://security.archlinux.org/AVG-1690 https://blog.semmle.com/libssh2-integer-overflow-CVE-2019-17498/ https://github.com/libssh2/libssh2/commit/dedcbd106f8e52d5586b0205bc7677e4c9868f9c https://github.com/libssh2/libssh2/pull/402/commits/1c6fa92b77e34d089493fe6d3e2c6c8775858b94 |
This task depends upon
Closed by Felix Yan (felixonmars)
Friday, 19 March 2021, 14:31 GMT
Reason for closing: Fixed
Additional comments about closing: libssh2 1.9.0-3
Friday, 19 March 2021, 14:31 GMT
Reason for closing: Fixed
Additional comments about closing: libssh2 1.9.0-3