FlawAtlas
Search the atlas
SUSE-SU-2024:0543-1 Not scored

Security update for libssh2_org

This update for libssh2_org fixes the following issues: - Always add the KEX pseudo-methods 'ext-info-c' and '[email protected]' when configuring custom method list. [bsc#1218971, CVE-2023-48795] * The strict-kex extension is announced in the list of available KEX methods. However, when the default KEX method list is modified or replaced, the extension is not added back automatically.

Exploit probability Not scored
Published February 20, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 12 SP5 libssh2_org
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 libssh2_org
SUSE:Linux Enterprise Software Development Kit 12 SP5 libssh2_org

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2024:0543-1

This update for libssh2_org fixes the following issues: - Always add the KEX pseudo-methods 'ext-info-c' and '[email protected]' when configuring custom method list. [bsc#1218971, CVE-2023-48795] * The strict-kex extension is announced in the list of available KEX methods. However, when the default KEX method list is modified or replaced, the extension is not added back automatically.

View original source

05 / REFERENCES

Further evidence