Mageia 2020-0324: libssh security update
Summary
The code in src/sftpserver.c did not verify the validity of certain pointersand expected them to be valid. A NULL pointer dereference could have been
occurred that typically causes a crash and thus a denial-of-service
(CVE-2020-16135).
References
- https://bugs.mageia.org/show_bug.cgi?id=27036
- https://www.debian.org/lts/security/2020/dla-2303
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16135
Resolution
MGASA-2020-0324 - Updated libssh packages fix security vulnerability
SRPMS
- 7/core/libssh-0.8.9-1.1.mga7