[ubuntu/eoan-updates] libssh 0.9.0-1ubuntu1.3 (Accepted)
Ubuntu Archive Robot
cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Tue Dec 10 18:28:15 UTC 2019
libssh (0.9.0-1ubuntu1.3) eoan-security; urgency=medium
* SECURITY UPDATE: unsanitized location in scp could lead to unwanted
command execution
- debian/patches/CVE-2019-14889-1.patch: add tests for SCP client in
tests/client/CMakeLists.txt, tests/client/torture_scp.c.
- debian/patches/CVE-2019-14889-2.patch: reformat code in scp/scp.c.
- debian/patches/CVE-2019-14889-3.patch: log SCP warnings received from
the server in src/scp.c.
- debian/patches/CVE-2019-14889-4.patch: add function to quote file
names in include/libssh/misc.h, src/misc.c.
- debian/patches/CVE-2019-14889-5.patch: add unit tests for
ssh_quote_file_name() in tests/unittests/torture_misc.c.
- debian/patches/CVE-2019-14889-6.patch: don't allow file path longer
than 32kb in src/scp.c.
- debian/patches/CVE-2019-14889-7.patch: quote location to be used on
shell in src/scp.c.
- CVE-2019-14889
Date: 2019-12-10 16:06:14.998396+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/libssh/0.9.0-1ubuntu1.3
-------------- next part --------------
Sorry, changesfile not available.
More information about the Eoan-changes
mailing list