Source: libssh
Version: 0.9.4-1
Severity: important
Tags: security upstream
Forwarded: https://bugs.libssh.org/T232
X-Debbugs-Cc: Debian Security Team <t...@security.debian.org>

Hi,

The following vulnerability was published for libssh.

CVE-2020-16135[0]:
| libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if
| ssh_buffer_new returns NULL.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2020-16135
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16135
[1] https://bugs.libssh.org/T232
[2] https://bugs.libssh.org/rLIBSSHe631ebb3e2247dd25e9678e6827c20dc73b73238
[3] https://gitlab.com/libssh/libssh-mirror/-/merge_requests/120

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to