Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2021.0441
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2021-0441)
Summary:The remote host is missing an update for the 'libssh' package(s) announced via the MGASA-2021-0441 advisory.
Description:Summary:
The remote host is missing an update for the 'libssh' package(s) announced via the MGASA-2021-0441 advisory.

Vulnerability Insight:
A flaw has been found in libssh in versions prior to 0.9.6. The SSH
protocol keeps track of two shared secrets during the lifetime of the
session. One of them is called secret_hash and the other session_id.
Initially, both of them are the same, but after key re-exchange, previous
session_id is kept and used as an input to new secret_hash. Historically,
both of these buffers had shared length variable, which worked as long as
these buffers were same. But the key re-exchange operation can also change
the key exchange method, which can be based on hash of different size,
eventually creating 'secret_hash' of different size than the session_id
has. This becomes an issue when the session_id memory is zeroed or when it
is used again during second key re-exchange. (CVE-2021-3634)

Affected Software/OS:
'libssh' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-3634
https://security.netapp.com/advisory/ntap-20211004-0003/
Debian Security Information: DSA-4965 (Google Search)
https://www.debian.org/security/2021/dsa-4965
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JKYD3ZRAMDAQX3ZW6THHUF3GXN7FF6B4/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SVWAAB2XMKEUMPMDALINKAA4U2QM4LNG/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DRK67AJCWYYVAGF5SGAHNZXCX3PN3ZFP/
https://security.gentoo.org/glsa/202312-05
https://bugzilla.redhat.com/show_bug.cgi?id=1978810
https://www.oracle.com/security-alerts/cpujan2022.html
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.