[El-errata] ELSA-2019-1652 Important: Oracle Linux 6 libssh2 security update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Tue Jul 2 18:26:02 PDT 2019
Oracle Linux Security Advisory ELSA-2019-1652
http://linux.oracle.com/errata/ELSA-2019-1652.html
The following updated rpms for Oracle Linux 6 have been uploaded to the
Unbreakable Linux Network:
i386:
libssh2-1.4.2-3.0.1.el6_10.1.i686.rpm
libssh2-devel-1.4.2-3.0.1.el6_10.1.i686.rpm
libssh2-docs-1.4.2-3.0.1.el6_10.1.i686.rpm
x86_64:
libssh2-1.4.2-3.0.1.el6_10.1.i686.rpm
libssh2-1.4.2-3.0.1.el6_10.1.x86_64.rpm
libssh2-devel-1.4.2-3.0.1.el6_10.1.i686.rpm
libssh2-devel-1.4.2-3.0.1.el6_10.1.x86_64.rpm
libssh2-docs-1.4.2-3.0.1.el6_10.1.x86_64.rpm
SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/libssh2-1.4.2-3.0.1.el6_10.1.src.rpm
Description of changes:
[1.4.2-3.0.1.el6_10.1]
- [Orabug: 29909723] Added patch CVE-2019-3862. (qing.lin at oracle.com)
Added Additional length checks to prevent out-of-bounds (CVE-2019-3862)
[1.4.2-3.el6_10.1]
- fix integer overflow in keyboard interactive handling that allows
out-of-bounds writes (CVE-2019-3863)
- fix integer overflow in SSH packet processing channel resulting in out
of bounds write (CVE-2019-3857)
- fix integer overflow in keyboard interactive handling resulting in out
of bounds write (CVE-2019-3856)
- fix integer overflow in transport read resulting in out of bounds
write (CVE-2019-3855)
- use secrects of the appropriate length in Diffie-Hellman (CVE-2016-0787)
More information about the El-errata
mailing list