[El-errata] ELSA-2019-0679 Important: Oracle Linux 7 libssh2 security update (aarch64)
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Fri Mar 29 05:37:39 PDT 2019
Oracle Linux Security Advisory ELSA-2019-0679
http://linux.oracle.com/errata/ELSA-2019-0679.html
The following updated rpms for Oracle Linux 7 have been uploaded to the
Unbreakable Linux Network:
aarch64:
libssh2-1.4.3-12.el7_6.2.aarch64.rpm
libssh2-devel-1.4.3-12.el7_6.2.aarch64.rpm
libssh2-docs-1.4.3-12.el7_6.2.noarch.rpm
SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/libssh2-1.4.3-12.el7_6.2.src.rpm
Description of changes:
[1.4.3-12.el7_6.2]
- sanitize public header file (detected by rpmdiff)
[1.4.3-12.el7_6.1]
- fix integer overflow in keyboard interactive handling that allows
out-of-bounds writes (CVE-2019-3863)
- fix integer overflow in SSH packet processing channel resulting in out
of bounds write (CVE-2019-3857)
- fix integer overflow in keyboard interactive handling resulting in out
of bounds write (CVE-2019-3856)
- fix integer overflow in transport read resulting in out of bounds
write (CVE-2019-3855)
More information about the El-errata
mailing list