Mageia 2020-0171: libssh security update
Updated libssh packages fix security vulnerability: A malicious client or server could crash the counterpart implemented with libssh AES-CTR ciphers are used and don't get fully...
Summary
Updated libssh packages fix security vulnerability:
A malicious client or server could crash the counterpart implemented
with libssh AES-CTR ciphers are used and don't get fully initialized.
It will crash when it tries to cleanup the AES-CTR ciphers when
closing the connection (CVE-2020-1730).
References
- https://bugs.mageia.org/show_bug.cgi?id=26462
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1730
Resolution
MGASA-2020-0171 - Updated libssh packages fix security vulnerability
SRPMS
- 7/core/libssh-0.8.9-1.mga7