Synopsis:          Moderate: libssh2 security update
Advisory ID:       SLSA-2016:0428-1
Issue Date:        2016-03-10
CVE Numbers:       CVE-2016-0787
--

A type confusion issue was found in the way libssh2 generated ephemeral
secrets for the diffie-hellman-group1 and diffie-hellman-group14 key
exchange methods. This would cause an SSHv2 Diffie-Hellman handshake to
use significantly less secure random parameters. (CVE-2016-0787)

After installing these updated packages, all running applications using
libssh2 must be restarted for this update to take effect.
--

SL6
  x86_64
    libssh2-1.4.2-2.el6_7.1.i686.rpm
    libssh2-1.4.2-2.el6_7.1.x86_64.rpm
    libssh2-debuginfo-1.4.2-2.el6_7.1.i686.rpm
    libssh2-debuginfo-1.4.2-2.el6_7.1.x86_64.rpm
    libssh2-devel-1.4.2-2.el6_7.1.i686.rpm
    libssh2-devel-1.4.2-2.el6_7.1.x86_64.rpm
    libssh2-docs-1.4.2-2.el6_7.1.x86_64.rpm
  i386
    libssh2-1.4.2-2.el6_7.1.i686.rpm
    libssh2-debuginfo-1.4.2-2.el6_7.1.i686.rpm
    libssh2-devel-1.4.2-2.el6_7.1.i686.rpm
    libssh2-docs-1.4.2-2.el6_7.1.i686.rpm
SL7
  x86_64
    libssh2-1.4.3-10.el7_2.1.i686.rpm
    libssh2-1.4.3-10.el7_2.1.x86_64.rpm
    libssh2-debuginfo-1.4.3-10.el7_2.1.i686.rpm
    libssh2-debuginfo-1.4.3-10.el7_2.1.x86_64.rpm
    libssh2-devel-1.4.3-10.el7_2.1.i686.rpm
    libssh2-devel-1.4.3-10.el7_2.1.x86_64.rpm
  noarch
    libssh2-docs-1.4.3-10.el7_2.1.noarch.rpm

- Scientific Linux Development Team