ELA-956-1 libssh2 security update

out of bound memory

2023-09-23
Packagelibssh2
Version1.4.3-4.1+deb8u7 (jessie), 1.7.0-1+deb9u3 (stretch)
Related CVEs CVE-2020-22218


An issue has been found in libssh2, an SSH2 client-side library, in function _libssh2_packet_add(), which could allow attackers to access out of bounds memory.



For Debian 8 jessie, these problems have been fixed in version 1.4.3-4.1+deb8u7.

For Debian 9 stretch, these problems have been fixed in version 1.7.0-1+deb9u3.

We recommend that you upgrade your libssh2 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.