Two security issues have been discovered in libssh, a tiny C SSH library: CVE-2023-1667 Philip Turnbull discovered a NULL pointer dereference which could result in denial of service. CVE-2023-2283 Kevin Backhouse discovered that pki_verify_data_signature() may fail to correctly validate authentication in memory pressure situations. For the stable distribution (bullseye), these problems have been fixed in version 0.9.7-0+deb11u1. We recommend that you upgrade your libssh packages. For the detailed security status of libssh please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libssh
Two security issues have been discovered in libssh, a tiny C SSH library:
Philip Turnbull discovered a NULL pointer dereference which could result in denial of service.
Kevin Backhouse discovered that pki_verify_data_signature() may fail to correctly validate authentication in memory pressure situations.
For the stable distribution (bullseye), these problems have been fixed in version 0.9.7-0+deb11u1.
We recommend that you upgrade your libssh packages.
For the detailed security status of libssh please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libssh