Rocky Linux 8 : libssh (RLSA-2020:4545)

high Nessus Plugin ID 184708

Synopsis

The remote Rocky Linux host is missing one or more security updates.

Description

The remote Rocky Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RLSA-2020:4545 advisory.

- A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8.
When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target. (CVE-2019-14889)

- A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability. (CVE-2020-1730)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://errata.rockylinux.org/RLSA-2020:4545

https://bugzilla.redhat.com/show_bug.cgi?id=1733914

https://bugzilla.redhat.com/show_bug.cgi?id=1772523

https://bugzilla.redhat.com/show_bug.cgi?id=1801998

https://bugzilla.redhat.com/show_bug.cgi?id=1804797

https://bugzilla.redhat.com/show_bug.cgi?id=1821339

https://bugzilla.redhat.com/show_bug.cgi?id=1849071

Plugin Details

Severity: High

ID: 184708

File Name: rocky_linux_RLSA-2020-4545.nasl

Version: 1.0

Type: local

Published: 11/6/2023

Updated: 11/6/2023

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2019-14889

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:rocky:linux:libssh, p-cpe:/a:rocky:linux:libssh-config, p-cpe:/a:rocky:linux:libssh-debuginfo, p-cpe:/a:rocky:linux:libssh-debugsource, p-cpe:/a:rocky:linux:libssh-devel, cpe:/o:rocky:linux:8

Required KB Items: Host/local_checks_enabled, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 11/3/2020

Vulnerability Publication Date: 12/10/2019

Reference Information

CVE: CVE-2019-14889, CVE-2020-1730

IAVA: 2020-A-0203