[El-errata] ELSA-2019-0679 Important: Oracle Linux 7 libssh2 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Mar 28 14:25:26 PDT 2019


Oracle Linux Security Advisory ELSA-2019-0679

http://linux.oracle.com/errata/ELSA-2019-0679.html

The following updated rpms for Oracle Linux 7 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
libssh2-1.4.3-12.el7_6.2.i686.rpm
libssh2-1.4.3-12.el7_6.2.x86_64.rpm
libssh2-devel-1.4.3-12.el7_6.2.i686.rpm
libssh2-devel-1.4.3-12.el7_6.2.x86_64.rpm
libssh2-docs-1.4.3-12.el7_6.2.noarch.rpm


SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/libssh2-1.4.3-12.el7_6.2.src.rpm



Description of changes:

[1.4.3-12.el7_6.2]
- sanitize public header file (detected by rpmdiff)

[1.4.3-12.el7_6.1]
- fix integer overflow in keyboard interactive handling that allows 
out-of-bounds writes (CVE-2019-3863)
- fix integer overflow in SSH packet processing channel resulting in out 
of bounds write (CVE-2019-3857)
- fix integer overflow in keyboard interactive handling resulting in out 
of bounds write (CVE-2019-3856)
- fix integer overflow in transport read resulting in out of bounds 
write (CVE-2019-3855)





More information about the El-errata mailing list