[ubuntu/groovy-proposed] libssh 0.9.4-1ubuntu2 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Mon Aug 3 14:15:12 UTC 2020


libssh (0.9.4-1ubuntu2) groovy; urgency=medium

  * SECURITY UPDATE: NULL pointer dereference
    - debian/patches/CVE-2020-16135-*.patch: fix a NULL dereference
      checking the return of ssh_buffer_new() and added others checks
      in src/sftpservcer.c, src/buffer.c.
    - CVE-2020-16135

Date: Fri, 31 Jul 2020 15:19:13 -0300
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/libssh/0.9.4-1ubuntu2
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 31 Jul 2020 15:19:13 -0300
Source: libssh
Architecture: source
Version: 0.9.4-1ubuntu2
Distribution: groovy
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Leonidas S. Barbosa <leo.barbosa at canonical.com>
Changes:
 libssh (0.9.4-1ubuntu2) groovy; urgency=medium
 .
   * SECURITY UPDATE: NULL pointer dereference
     - debian/patches/CVE-2020-16135-*.patch: fix a NULL dereference
       checking the return of ssh_buffer_new() and added others checks
       in src/sftpservcer.c, src/buffer.c.
     - CVE-2020-16135
Checksums-Sha1:
 1038136746e417486fdec5dc287d56b8b1a3e4a9 2771 libssh_0.9.4-1ubuntu2.dsc
 7d49b5db86c291dafc9cb444444a7f82edfa3575 28748 libssh_0.9.4-1ubuntu2.debian.tar.xz
 9c50425dfb92f1650dd61954193310ecaf97cf14 8352 libssh_0.9.4-1ubuntu2_source.buildinfo
Checksums-Sha256:
 f59d9ac6b3097b1484815002cda2e3d5ee49d8306750e55db56b26f5464e1ccd 2771 libssh_0.9.4-1ubuntu2.dsc
 44e6847ea6217664ff793d799acd4892ebef5f580661eda276d378057304c2ff 28748 libssh_0.9.4-1ubuntu2.debian.tar.xz
 5a3f1004523cc174bbfa574c0e95936bc10bde0e1070bf258046e90fb87a946c 8352 libssh_0.9.4-1ubuntu2_source.buildinfo
Files:
 ee4099c84e82b9148307fdb617062046 2771 libs optional libssh_0.9.4-1ubuntu2.dsc
 2b8107972fc9b6003e67b246a0d1cede 28748 libs optional libssh_0.9.4-1ubuntu2.debian.tar.xz
 3cac49d89df651a4d55639db5795631b 8352 libs optional libssh_0.9.4-1ubuntu2_source.buildinfo
Original-Maintainer: Laurent Bigonville <bigon at debian.org>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl8oGvQACgkQZWnYVadE
vpMN9hAAjS6hIi2Prp1aI9obvkyAvaBif5NiKXcUaT5SRWOKaWGgxnnLtnpLZxvs
AwxRd040YJDZ5JLRq1v/EgkRrcC56rh8+exszuHgru8rs4YyAMv6scnxSyubrcWK
j7FpuBJZrDRT3k1mmLQqWBSBxcCR48SGGATSDlWhQqY/UgskmS87sPHvSt3hAq+n
DjFL5vYirMHKxAdx1ETTKYxUuLZKut563s8HltFuvXVGFtg2oAVSFb9hxyoaKzGh
0IVROPREgCjOrxz7Fd6pV1bT088bAYAoSn0xIlqcHXTtUu3StWW1BnYK4vj/MDqH
riC2+FjZPkglhdoFet8GuoIA+I8F/n9GRDM6DGOy1eKrGGM7Wqezn2xcglc3f0xJ
Jg21KDat373NUVds+PZytMLrh6nHMYXc0rAxRXYEQrv/02AaRJhqRVosKBeuXizJ
/0dAzhHQB8YRf5uh1E4U2M9Wxi34vXGugZI2/CLSHJ8xdrX3fiiRa9W+/0IwS4z+
oRmX3eWUWBOZ6aoxQWSjmJ5CZtnNl1P4FIpxEgTvUDwXoPshpiV2BS+fPXeRCIrX
iwa7oBo9WFDGYFHdbNEjiyTAc/9k+IJs1MGZDa0wc+QZAJ3DDcoL1c7TzV580Ykv
FLDPsd5Df6clSPKyiA1AV4GQ0w5o1LRXx7PAO7TwS+DvUPqLJsw=
=0bmK
-----END PGP SIGNATURE-----


More information about the Groovy-changes mailing list