SCIENTIFIC-LINUX-ERRATA Archives

March 2016

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Thu, 10 Mar 2016 18:46:45 -0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (42 lines)
Synopsis:          Moderate: libssh2 security update
Advisory ID:       SLSA-2016:0428-1
Issue Date:        2016-03-10
CVE Numbers:       CVE-2016-0787
--

A type confusion issue was found in the way libssh2 generated ephemeral
secrets for the diffie-hellman-group1 and diffie-hellman-group14 key
exchange methods. This would cause an SSHv2 Diffie-Hellman handshake to
use significantly less secure random parameters. (CVE-2016-0787)

After installing these updated packages, all running applications using
libssh2 must be restarted for this update to take effect.
--

SL6
  x86_64
    libssh2-1.4.2-2.el6_7.1.i686.rpm
    libssh2-1.4.2-2.el6_7.1.x86_64.rpm
    libssh2-debuginfo-1.4.2-2.el6_7.1.i686.rpm
    libssh2-debuginfo-1.4.2-2.el6_7.1.x86_64.rpm
    libssh2-devel-1.4.2-2.el6_7.1.i686.rpm
    libssh2-devel-1.4.2-2.el6_7.1.x86_64.rpm
    libssh2-docs-1.4.2-2.el6_7.1.x86_64.rpm
  i386
    libssh2-1.4.2-2.el6_7.1.i686.rpm
    libssh2-debuginfo-1.4.2-2.el6_7.1.i686.rpm
    libssh2-devel-1.4.2-2.el6_7.1.i686.rpm
    libssh2-docs-1.4.2-2.el6_7.1.i686.rpm
SL7
  x86_64
    libssh2-1.4.3-10.el7_2.1.i686.rpm
    libssh2-1.4.3-10.el7_2.1.x86_64.rpm
    libssh2-debuginfo-1.4.3-10.el7_2.1.i686.rpm
    libssh2-debuginfo-1.4.3-10.el7_2.1.x86_64.rpm
    libssh2-devel-1.4.3-10.el7_2.1.i686.rpm
    libssh2-devel-1.4.3-10.el7_2.1.x86_64.rpm
  noarch
    libssh2-docs-1.4.3-10.el7_2.1.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2