Lucene search

K
slackwareSlackware Linux ProjectSSA-2018-289-01
HistoryOct 17, 2018 - 3:52 a.m.

[slackware-security] libssh

2018-10-1703:52:18
Slackware Linux Project
www.slackware.com
70

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS

0.136

Percentile

95.7%

New libssh packages are available for Slackware 14.0, 14.1, 14.2, and -current
to fix a security issue.

Here are the details from the Slackware 14.2 ChangeLog:

patches/packages/libssh-0.7.6-i586-1_slack14.2.txz: Upgraded.
Fixed authentication bypass vulnerability.
For more information, see:
https://www.libssh.org/2018/10/16/libssh-0-8-4-and-0-7-6-security-and-bugfix-release/
https://vulners.com/cve/CVE-2018-10933
(* Security fix *)

Where to find the new packages:

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 14.0:
ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/libssh-0.7.6-i486-1_slack14.0.txz

Updated package for Slackware x86_64 14.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/libssh-0.7.6-x86_64-1_slack14.0.txz

Updated package for Slackware 14.1:
ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/libssh-0.7.6-i486-1_slack14.1.txz

Updated package for Slackware x86_64 14.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/libssh-0.7.6-x86_64-1_slack14.1.txz

Updated package for Slackware 14.2:
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/libssh-0.7.6-i586-1_slack14.2.txz

Updated package for Slackware x86_64 14.2:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/libssh-0.7.6-x86_64-1_slack14.2.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/l/libssh-0.7.6-i586-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/l/libssh-0.7.6-x86_64-1.txz

MD5 signatures:

Slackware 14.0 package:
132daeab4d33314c642cc11ed84a93b9 libssh-0.7.6-i486-1_slack14.0.txz

Slackware x86_64 14.0 package:
e4fe9892bafa9a8432b10f3c907759e9 libssh-0.7.6-x86_64-1_slack14.0.txz

Slackware 14.1 package:
95f7c0251472e8d189ccdbdaa228a429 libssh-0.7.6-i486-1_slack14.1.txz

Slackware x86_64 14.1 package:
1537ef4d99a40806e9838294c654e7ad libssh-0.7.6-x86_64-1_slack14.1.txz

Slackware 14.2 package:
4395d549c794aaf2a4ea1ce8c0cf5cb4 libssh-0.7.6-i586-1_slack14.2.txz

Slackware x86_64 14.2 package:
712fada9b823ed7982575cb89f0d709f libssh-0.7.6-x86_64-1_slack14.2.txz

Slackware -current package:
91ef4552de2c81098c9f5c3e0b1f0906 l/libssh-0.7.6-i586-1.txz

Slackware x86_64 -current package:
2cdb11e6bd6d140e0875d93aec1b0bac l/libssh-0.7.6-x86_64-1.txz

Installation instructions:

Upgrade the package as root:
> upgradepkg libssh-0.7.6-i586-1_slack14.2.txz

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS

0.136

Percentile

95.7%