libssh Multiple Buffer Overflow and Denial of Service Vulnerabilities
BID:56604
Info
libssh Multiple Buffer Overflow and Denial of Service Vulnerabilities
| Bugtraq ID: | 56604 |
| Class: | Unknown |
| CVE: |
CVE-2012-4559 CVE-2012-4560 CVE-2012-4561 CVE-2012-4562 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2012 12:00AM |
| Updated: | Apr 13 2015 08:33PM |
| Credit: | Xi Wang and Florian Weimer of the Red Hat Product Security Team |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise SDK 11 SP2 SuSE SUSE Linux Enterprise Desktop 11 SP2 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 Gentoo Linux |
| Not Vulnerable: | |
Solution / Fix
libssh Multiple Buffer Overflow and Denial of Service Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2011 x86_64
Mandriva Linux Mandrake 2011
Mandriva Business Server 1 X86 64
Solution:
Vendor updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2011 x86_64
-
Mandriva lib64ssh-devel-0.5.3-0.1-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64ssh4-0.5.3-0.1-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva libssh-devel-0.5.3-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva libssh4-0.5.3-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Business Server 1 X86 64
-
Mandriva lib64ssh-devel-0.5.2-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64ssh4-0.5.2-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
libssh Multiple Buffer Overflow and Denial of Service Vulnerabilities
References:
References:
- Bug 871612 - (CVE-2012-4559) CVE-2012-4559 libssh: multiple double free() flaws (Bugzilla)
- Bug 871614 - (CVE-2012-4560) CVE-2012-4560 libssh: multiple buffer overflow flaw (Bugzilla)
- Bug 871617 - (CVE-2012-4561) CVE-2012-4561 libssh: multiple invalid free() flaws (Bugzilla)
- Bug 871620 - (CVE-2012-4562) CVE-2012-4562 libssh: multiple improper overflow ch (Bugzilla)
- libssh 0.5.3 (SECURITY RELEASE) (libssh)
- libssh Homepage (libssh)