First published: Wed Jan 31 2024(Updated: )
libssh is a library which implements the SSH protocol. It can be used to implement client and server applications.<br>Security Fix(es):<br><li> ssh: Prefix truncation attack on Binary Packet Protocol (BPP) (CVE-2023-48795)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libssh | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh-config | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh-debuginfo | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh-debuginfo | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh-debugsource | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh-debugsource | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh-devel | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh-devel | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh-debuginfo | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh-debugsource | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh-devel | <0.9.6-13.el8_9 | 0.9.6-13.el8_9 |
redhat/libssh | <0.9.6-13.el8_9.aa | 0.9.6-13.el8_9.aa |
redhat/libssh-debuginfo | <0.9.6-13.el8_9.aa | 0.9.6-13.el8_9.aa |
redhat/libssh-debugsource | <0.9.6-13.el8_9.aa | 0.9.6-13.el8_9.aa |
redhat/libssh-devel | <0.9.6-13.el8_9.aa | 0.9.6-13.el8_9.aa |
Red Hat Enterprise Linux for ARM 64 | ||
Red Hat Enterprise Linux for Power, little endian - Extended Update Support | ||
Red Hat Enterprise Linux Server for IBM z Systems |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:0628 is classified as moderate.
To fix RHSA-2024:0628, upgrade the affected packages to version 0.9.6-13.el8_9 or later.
RHSA-2024:0628 affects the libssh library used in several Red Hat Enterprise Linux distributions.
CVE-2023-48795 is a vulnerability that involves a prefix truncation attack on the Binary Packet Protocol (BPP).
No, RHSA-2024:0628 is specific to Red Hat Enterprise Linux for ARM 64, Power, IBM z Systems, and associated packages.