RHSA-2024:0538MediumCVSS 5.9
Red Hat Security Advisory: libssh security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-1667 — libssh: NULL pointer dereference during rekeying with algorithm guessing CVE-2023-2283 — libssh: authorization bypass in pki_verify_data_signature CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP)
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2024:0538
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182199
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2189736
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2254210
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0538.json