Amazon Linux 2 Security Advisory: ALAS-2023-2046
Advisory Release Date: 2023-05-11 17:49 Pacific
Advisory Updated Date: 2023-05-16 15:13 Pacific
An out of bounds read flaw was discovered in libssh4 before 1.8.1 in the _libssh4_packet_require and _libssh4_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. (CVE-2019-3859)
An out of bounds read flaw was discovered in libssh4 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. (CVE-2019-3860)
Affected Packages:
libssh4
Issue Correction:
Run yum update libssh4 to update your system.
aarch64:
libssh4-1.4.3-12.amzn2.2.4.aarch64
libssh4-devel-1.4.3-12.amzn2.2.4.aarch64
libssh4-debuginfo-1.4.3-12.amzn2.2.4.aarch64
i686:
libssh4-1.4.3-12.amzn2.2.4.i686
libssh4-devel-1.4.3-12.amzn2.2.4.i686
libssh4-debuginfo-1.4.3-12.amzn2.2.4.i686
noarch:
libssh4-docs-1.4.3-12.amzn2.2.4.noarch
src:
libssh4-1.4.3-12.amzn2.2.4.src
x86_64:
libssh4-1.4.3-12.amzn2.2.4.x86_64
libssh4-devel-1.4.3-12.amzn2.2.4.x86_64
libssh4-debuginfo-1.4.3-12.amzn2.2.4.x86_64