MGASA-2023-0357 - Updated libssh packages fix security vulnerabilities

Publication date: 29 Dec 2023
URL: https://advisories.mageia.org/MGASA-2023-0357.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2023-6004,
     CVE-2023-6918,
     CVE-2023-48795

New version 0.10.6 for fixing security vulnerabilities of CVE-2023-6004,
CVE-2023-48795 [Prefix Truncation Attacks in SSH Specification (Terrapin
Attack)] and CVE-2023-6918.

References:
- https://bugs.mageia.org/show_bug.cgi?id=32660
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6004
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6918
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795

SRPMS:
- 9/core/libssh-0.10.6-1.mga9

Mageia 2023-0357: libssh security update

New version 0.10.6 for fixing security vulnerabilities of CVE-2023-6004, CVE-2023-48795 [Prefix Truncation Attacks in SSH Specification (Terrapin Attack)] and CVE-2023-6918

Summary

New version 0.10.6 for fixing security vulnerabilities of CVE-2023-6004, CVE-2023-48795 [Prefix Truncation Attacks in SSH Specification (Terrapin Attack)] and CVE-2023-6918.

References

- https://bugs.mageia.org/show_bug.cgi?id=32660

- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6004

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6918

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-48795

Resolution

MGASA-2023-0357 - Updated libssh packages fix security vulnerabilities

SRPMS

- 9/core/libssh-0.10.6-1.mga9

Severity
Publication date: 29 Dec 2023
URL: https://advisories.mageia.org/MGASA-2023-0357.html
Type: security
CVE: CVE-2023-6004, CVE-2023-6918, CVE-2023-48795

Related News