[El-errata] ELSA-2019-1652 Important: Oracle Linux 6 libssh2 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Jul 2 18:26:02 PDT 2019


Oracle Linux Security Advisory ELSA-2019-1652

http://linux.oracle.com/errata/ELSA-2019-1652.html

The following updated rpms for Oracle Linux 6 have been uploaded to the 
Unbreakable Linux Network:

i386:
libssh2-1.4.2-3.0.1.el6_10.1.i686.rpm
libssh2-devel-1.4.2-3.0.1.el6_10.1.i686.rpm
libssh2-docs-1.4.2-3.0.1.el6_10.1.i686.rpm

x86_64:
libssh2-1.4.2-3.0.1.el6_10.1.i686.rpm
libssh2-1.4.2-3.0.1.el6_10.1.x86_64.rpm
libssh2-devel-1.4.2-3.0.1.el6_10.1.i686.rpm
libssh2-devel-1.4.2-3.0.1.el6_10.1.x86_64.rpm
libssh2-docs-1.4.2-3.0.1.el6_10.1.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/libssh2-1.4.2-3.0.1.el6_10.1.src.rpm



Description of changes:

[1.4.2-3.0.1.el6_10.1]
- [Orabug: 29909723] Added patch CVE-2019-3862. (qing.lin at oracle.com)
   Added Additional length checks to prevent out-of-bounds (CVE-2019-3862)

[1.4.2-3.el6_10.1]
- fix integer overflow in keyboard interactive handling that allows 
out-of-bounds writes (CVE-2019-3863)
- fix integer overflow in SSH packet processing channel resulting in out 
of bounds write (CVE-2019-3857)
- fix integer overflow in keyboard interactive handling resulting in out 
of bounds write (CVE-2019-3856)
- fix integer overflow in transport read resulting in out of bounds 
write (CVE-2019-3855)

- use secrects of the appropriate length in Diffie-Hellman (CVE-2016-0787)




More information about the El-errata mailing list