Upstream information

CVE-2016-0787 at MITRE

Description

The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.30
Vector AV:N/AC:M/Au:N/C:P/I:N/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
CVSS v3 Scores
  National Vulnerability Database
Base Score 5.9
Vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Access Vector Network
Access Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact None
SUSE Bugzilla entries: 967026 [RESOLVED / FIXED], 968174 [RESOLVED / DUPLICATE], 974691 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 11 SP4
  • libssh2-1 >= 1.2.9-4.2.6.1
  • libssh2_org >= 1.2.9-4.2.6.1
Patchnames:
sledsp4-libssh2_org-12445
SUSE Linux Enterprise Desktop 12
  • libssh2-1 >= 1.4.3-16.1
  • libssh2-1-32bit >= 1.4.3-16.1
  • libssh2_org >= 1.4.3-16.1
Patchnames:
SUSE-SLE-DESKTOP-12-2016-413
SUSE Linux Enterprise Desktop 12 SP1
  • libssh2-1 >= 1.4.3-16.1
  • libssh2-1-32bit >= 1.4.3-16.1
  • libssh2_org >= 1.4.3-16.1
Patchnames:
SUSE-SLE-DESKTOP-12-SP1-2016-413
SUSE Linux Enterprise Desktop 12 SP2
  • libssh2-1 >= 1.4.3-19.1
  • libssh2-1-32bit >= 1.4.3-19.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA libssh2-1
SUSE Linux Enterprise Server 11 SP4
  • libssh2-1 >= 1.2.9-4.2.6.1
  • libssh2_org >= 1.2.9-4.2.6.1
Patchnames:
slessp4-libssh2_org-12445
SUSE Linux Enterprise Server 12
  • libssh2-1 >= 1.4.3-16.1
  • libssh2-1-32bit >= 1.4.3-16.1
  • libssh2_org >= 1.4.3-16.1
Patchnames:
SUSE-SLE-SERVER-12-2016-413
SUSE Linux Enterprise Server 12 SP1
  • libssh2-1 >= 1.4.3-16.1
  • libssh2-1-32bit >= 1.4.3-16.1
  • libssh2_org >= 1.4.3-16.1
Patchnames:
SUSE-SLE-SERVER-12-SP1-2016-413
SUSE Linux Enterprise Server 12 SP2
  • libssh2-1 >= 1.4.3-19.1
  • libssh2-1-32bit >= 1.4.3-19.1
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA libssh2-1
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • libssh2-1 >= 1.4.3-19.1
Patchnames:
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA libssh2-1
SUSE Linux Enterprise Software Development Kit 11 SP4
  • libssh2-1 >= 1.2.9-4.2.6.1
  • libssh2-1-32bit >= 1.2.9-4.2.6.1
  • libssh2-1-x86 >= 1.2.9-4.2.6.1
  • libssh2-devel >= 1.2.9-4.2.6.1
  • libssh2_org >= 1.2.9-4.2.6.1
Patchnames:
sdksp4-libssh2_org-12445
SUSE Linux Enterprise Software Development Kit 12
  • libssh2-devel >= 1.4.3-16.1
  • libssh2_org >= 1.4.3-16.1
Patchnames:
SUSE-SLE-SDK-12-2016-413
SUSE Linux Enterprise Software Development Kit 12 SP1
  • libssh2-devel >= 1.4.3-16.1
  • libssh2_org >= 1.4.3-16.1
Patchnames:
SUSE-SLE-SDK-12-SP1-2016-413
SUSE Linux Enterprise Software Development Kit 12 SP2
  • libssh2-devel >= 1.4.3-19.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP2 GA libssh2-devel
openSUSE 13.2
  • libssh2-1 >= 1.5.0-9.7.1
  • libssh2-1-32bit >= 1.5.0-9.7.1
  • libssh2-1-debuginfo >= 1.5.0-9.7.1
  • libssh2-1-debuginfo-32bit >= 1.5.0-9.7.1
  • libssh2-devel >= 1.5.0-9.7.1
  • libssh2_org >= 1.5.0-9.7.1
  • libssh2_org-debugsource >= 1.5.0-9.7.1
Patchnames:
openSUSE-2016-295
openSUSE Leap 42.1
  • libssh2-1 >= 1.4.3-12.1
  • libssh2-1-32bit >= 1.4.3-12.1
  • libssh2-1-debuginfo >= 1.4.3-12.1
  • libssh2-1-debuginfo-32bit >= 1.4.3-12.1
  • libssh2-devel >= 1.4.3-12.1
  • libssh2_org >= 1.4.3-12.1
  • libssh2_org-debugsource >= 1.4.3-12.1
Patchnames:
openSUSE-2016-388
openSUSE Leap 42.2
  • libssh2-1 >= 1.4.3-16.1
Patchnames:
openSUSE Leap 42.2 GA libssh2-1
openSUSE Tumbleweed
  • libssh2-1 >= 1.7.0-1.5
  • libssh2-1-32bit >= 1.7.0-1.5
  • libssh2-devel >= 1.7.0-1.5
Patchnames:
openSUSE Tumbleweed GA libssh2-1