openSUSE Security Update : libssh2_org (openSUSE-2016-388)
Medium Nessus Plugin ID 90166
SynopsisThe remote openSUSE host is missing a security update.
DescriptionThis update for libssh2_org fixes the following issues :
Security issue fixed :
- CVE-2016-0787 (bsc#967026): Weakness in diffie-hellman secret key generation lead to much shorter DH groups then needed, which could be used to retrieve server keys.
A feature was added :
- Support of SHA256 digests for DH group exchanges was added (fate#320343, bsc#961964)
Bug fixed :
- Properly detect EVP_aes_128_ctr at configure time (bsc#933336)
This update was imported from the SUSE:SLE-12:Update update project.
SolutionUpdate the affected libssh2_org packages.