Upstream information
Description
Multiple integer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (infinite loop or crash) and possibly execute arbitrary code via unspecified vectors, which triggers a buffer overflow, infinite loop, or possibly some other unspecified vulnerabilities.NVD CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 789827 SUSE Security Advisories:- SUSE-SU-2012:1520-1, published Wed, 21 Nov 2012 19:08:51 +0100 (CET)
- openSUSE-SU-2012:1620-1, published Fri, 7 Dec 2012 11:08:42 +0100 (CET)
- openSUSE-SU-2012:1622-1, published Fri, 7 Dec 2012 11:09:15 +0100 (CET)
- openSUSE-SU-2013:0130-1, published Wed, 23 Jan 2013 14:04:52 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Desktop 11 SP2 SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sle11-sp2-sdk.ppc sled11-sp2.x86 sle11-sp2-sdk.s390x sled11-sp2.x86-64 sle11-sp2-sdk.x86-64 sle11-sp2-sdk.ia64 sle11-sp2-sdk.x86 SAT Patch Nr: 7073 |
