FlawAtlas
Search the atlas
SUSE-SU-2024:0558-1 Not scored

Security update for libssh2_org

This update for libssh2_org fixes the following issues: - Always add the KEX pseudo-methods 'ext-info-c' and '[email protected]' when configuring custom method list. [bsc#1218971, CVE-2023-48795] * The strict-kex extension is announced in the list of available KEX methods. However, when the default KEX method list is modified or replaced, the extension is not added back automatically.

Exploit probability Not scored
Published February 20, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7.1 libssh2_org
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS libssh2_org
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS libssh2_org
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS libssh2_org
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS libssh2_org
SUSE:Linux Enterprise Micro 5.1 libssh2_org
SUSE:Linux Enterprise Micro 5.2 libssh2_org
SUSE:Linux Enterprise Micro 5.3 libssh2_org
SUSE:Linux Enterprise Micro 5.4 libssh2_org
SUSE:Linux Enterprise Micro 5.5 libssh2_org
SUSE:Linux Enterprise Module for Basesystem 15 SP5 libssh2_org
SUSE:Linux Enterprise Server 15 SP2-LTSS libssh2_org
SUSE:Linux Enterprise Server 15 SP3-LTSS libssh2_org
SUSE:Linux Enterprise Server 15 SP4-LTSS libssh2_org
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 libssh2_org
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 libssh2_org
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 libssh2_org
SUSE:Manager Proxy 4.3 libssh2_org
SUSE:Manager Server 4.3 libssh2_org
openSUSE:Leap 15.5 libssh2_org
openSUSE:Leap Micro 5.3 libssh2_org
openSUSE:Leap Micro 5.4 libssh2_org

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2024:0558-1

This update for libssh2_org fixes the following issues: - Always add the KEX pseudo-methods 'ext-info-c' and '[email protected]' when configuring custom method list. [bsc#1218971, CVE-2023-48795] * The strict-kex extension is announced in the list of available KEX methods. However, when the default KEX method list is modified or replaced, the extension is not added back automatically.

View original source

05 / REFERENCES

Further evidence