Oval Definition:oval:org.cisecurity:def:144
Revision Date:2016-02-08Version:2
Title:DSA-3182-1 -- libssh2 -- security update
Description:Mariusz Ziulek reported that libssh2, a SSH2 client-side library, was reading and using the SSH_MSG_KEXINIT packet without doing sufficient range checks when negotiating a new SSH session with a remote server. A malicious attacker could man in the middle a real server and cause a client using the libssh2 library to crash (denial of service) or otherwise read and use unintended memory areas in this process.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2015-1782
DSA-3182-1
Platform(s):Debian GNU/kFreeBSD 7.0
Debian GNU/Linux 7.0
Product(s):libssh2
Definition Synopsis
  • Debian 7 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND libssh2 is earlier than 0:1.4.2-1.1+deb7u1
  • BACK