USN-6371-1: libssh2 vulnerability
14 September 2023
libssh2 could be made to crash if it received specially crafted network traffic.
Releases
Packages
- libssh2 - Client-side C library implementing the SSH2 protocol
Details
It was discovered that libssh2 incorrectly handled memory
access. An attacker could possibly use this issue to cause
a crash.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
Ubuntu 18.04
Ubuntu 16.04
-
libssh2-1
-
1.5.0-2ubuntu0.1+esm2
Available with Ubuntu Pro
Ubuntu 14.04
-
libssh2-1
-
1.4.3-2ubuntu0.2+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.