Resource management error in libssh - CVE-2020-1730
Published: April 10, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper resource management while cleaning the AES-CTR ciphers when closing the connection. A remote attacker can initiate a connection to the client and server that supports AES-CTR ciphers and close the connection before ciphers are initialized, triggering a denial of service condition (service crash). The vulnerability affects both client and server implementations.
Affected software
Arch Linux
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Opensuse
openEuler
Fedora
libssh (Ubuntu package)
libssh (Alpine package)
imgbased (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
libssh-devel
libssh
libssh-debuginfo
libssh-debugsource
libssh-help
libssh (Red Hat package)
libssh4
libssh4-debuginfo-32bit
libssh4-32bit
libssh-config
libssh4-debuginfo
libssh4-32bit-debuginfo
redhat-virtualization-host (Red Hat package)
Service Telemetry Framework
Dell Secure Connect Gateway
Red Hat OpenShift Serverless
Quay
Red Hat Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
MySQL Workbench
PowerStore X
PowerStore T
Storage Resource Manager
EMC Cloud Tiering Appliance
Dell EMC Storage Monitoring and Reporting (SMR)
RSA Authentication Manager
How to mitigate CVE-2020-1730
libssh (Ubuntu package) - addressed in versions 0.8.0~20170825.94fa1e38-1ubuntu0.6, 0.9.0-1ubuntu1.4
libssh (Alpine package) - update to 0.8.9-r0
imgbased (Red Hat package) - update to 1.2.13-0.1.el8ev
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
Quay - update to 3.3.3
redhat-release-virtualization-host (Red Hat package) - update to 4.4.3-1.el8ev
libssh-devel - update to 0.9.4-1
libssh - update to 0.9.4-1
libssh-debuginfo - update to 0.9.4-1
libssh-debugsource - update to 0.9.4-1
libssh-help - update to 0.9.4-1
libssh - addressed in versions 0.9.4-1.fc31, 0.9.4-1.fc32, 0.9.4-2.fc31, 0.9.4-2.fc32
libssh (Red Hat package) - update to 0.9.4-2.el8
libssh4 - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh4-debuginfo-32bit - update to 0.9.8-3.12.2
libssh4-32bit - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh-config - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh-debugsource - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh4-debuginfo - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh-devel - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh4-32bit-debuginfo - update to 0.9.8-150200.13.3.1
PowerStore X - update to 3.2.1.4-2386214
PowerStore T - update to 4.0.0.2-2365061
redhat-virtualization-host (Red Hat package) - update to 4.4.3-20201116.0.el8_3
Storage Resource Manager - update to 4.10.0.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
Dell Secure Connect Gateway - update to 5.24.00.14
RSA Authentication Manager - update to 8.7 SP2 Patch 2
EMC Cloud Tiering Appliance - update to 13.2.0.2.29
External References
Related Security Bulletins
- Denial of service in libssh
- Arch Linux update for libssh
- Ubuntu update for libssh
- Gentoo update for libssh
- OpenSUSE Linux update for libssh
- Resource management error in libssh (Alpine package)
- Multiple vulnerabilities in MySQL Workbench
- Red Hat Enterprise Linux 8 update for libssh
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Red Hat update for Red Hat Virtualization
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- SUSE update for libssh
- SUSE update for libssh
- openEuler 20.03 LTS update for libssh-0.9.4-1
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Dell PowerStore X
- Multiple vulnerabilities in Dell PowerStore T Family
- Fedora 32 update for libssh
- Fedora 31 update for libssh
- Fedora 32 update for libssh
- Fedora 31 update for libssh
- RSA Authentication Manager update for third-party components