Vulnerability Bulletins

DSA-3182 libssh2 - security update

   
Affected software Debian
 
Mariusz Ziulek reported that libssh2, a SSH2 client-side library, wasreading and using the SSH_MSG_KEXINIT packet without doing sufficientrange checks when negotiating a new SSH session with a remote server. Amalicious attacker could man in the middle a real server and cause aclient using the libssh2 library to crash (denial of service) orotherwise read and use unintended memory areas in this process.

More info:

https://www.debian.org/security/2015/dsa-3182