Debian Security Advisory

DSA-4431-1 libssh2 -- security update

Date Reported:
13 Apr 2019
Affected Packages:
Security database references:
In the Debian bugtracking system: Bug 924965.
In Mitre's CVE dictionary: CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3858, CVE-2019-3859, CVE-2019-3860, CVE-2019-3861, CVE-2019-3862, CVE-2019-3863.
More information:

Chris Coulson discovered several vulnerabilities in libssh2, a SSH2 client-side library, which could result in denial of service, information leaks or the execution of arbitrary code.

For the stable distribution (stretch), these problems have been fixed in version 1.7.0-1+deb9u1.

We recommend that you upgrade your libssh2 packages.

For the detailed security status of libssh2 please refer to its security tracker page at: