UbuntuUpdates.org

Package "libssh2"

Name: libssh2

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • SSH2 client-side library
  • SSH2 client-side library (development headers)

Latest version: 1.11.0-2ubuntu0.1
Release: mantic (23.10)
Level: security
Repository: main

Links



Other versions of "libssh2" in Mantic

Repository Area Version
base main 1.11.0-2
updates main 1.11.0-2ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.11.0-2ubuntu0.1 2024-01-16 17:07:42 UTC

  libssh2 (1.11.0-2ubuntu0.1) mantic-security; urgency=medium

  * SECURITY UPDATE: Prefix truncation attack on BPP
    - debian/patches/CVE-2023-48795.patch: implement "strict key exchange"
      in src/kex.c, src/libssh2_priv.h, src/packet.c, src/packet.h,
      src/session.c, src/transport.c.
    - CVE-2023-48795

 -- Marc Deslauriers <email address hidden> Wed, 10 Jan 2024 12:32:11 -0500

CVE-2023-48795 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integri



About   -   Send Feedback to @ubuntu_updates