Vulnerability Bulletins |
DSA-3487 libssh2 - security update |
|
| Affected software | Debian |
|
Andreas Schneider reported that libssh2, a SSH2 client-side library,passes the number of bytes to a function that expects number of bitsduring the SSHv2 handshake when libssh2 is to get a suitable value forgroup order in the Diffie-Hellman negotiation. This weakenssignificantly the handshake security, potentially allowing aneavesdropper with enough resources to decrypt or intercept SSH sessions. More info: https://www.debian.org/security/2016/dsa-3487 |
|






