Advisories ยป MGASA-2020-0324

Updated libssh packages fix security vulnerability

Publication date: 18 Aug 2020
Modification date: 18 Aug 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-16135

Description

The code in src/sftpserver.c did not verify the validity of certain pointers
and expected them to be valid. A NULL pointer dereference could have been
occurred that typically causes a crash and thus a denial-of-service
(CVE-2020-16135).
                

References

SRPMS

7/core