安全公告详情

NS-SA-2021-0173

2021-09-24 11:21:20

简介

moderate: okular/libssh2 security update

严重级别

moderate

主题

An update for okular/libssh2 is now available for NewStart CGSL MAIN 5.05/CGSL CORE 5.05.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

okular: A document viewer.
libssh2: libssh2 is a library implementing the SSH2 protocol as defined by Internet Drafts: SECSH-TRANS(22), SECSH-USERAUTH(25), SECSH-CONNECTION(23), SECSH-ARCH(20), SECSH-FILEXFER(06)*, SECSH-DHGEX(04), and SECSH-NUMBERS(10).


Security Fix(es):
okular: KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.(CVE-2020-9359)
okular: bugfix
libssh2: In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server.(CVE-2019-17498)
libssh2: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 5.05.F11B5.

影响组件

  • okular
  • libssh2

影响产品

  • CGSL MAIN 5.05
  • CGSL CORE 5.05

更新包

{"fix":[{"product":"CGSL MAIN 5.05","pkgs":[{"binary":["okular-part-4.10.5-9.el7.x86_64.rpm","okular-libs-4.10.5-9.el7.x86_64.rpm","okular-4.10.5-9.el7.x86_64.rpm","okular-devel-4.10.5-9.el7.x86_64.rpm"],"source":"okular-4.10.5-9.el7.src.rpm"},{"binary":["libssh2-devel-1.8.0-4.el7.x86_64.rpm","libssh2-1.8.0-4.el7.x86_64.rpm","libssh2-docs-1.8.0-4.el7.noarch.rpm"],"source":"libssh2-1.8.0-4.el7.src.rpm"}]},{"product":"CGSL CORE 5.05","pkgs":[{"binary":["okular-part-4.10.5-9.el7.x86_64.rpm","okular-libs-4.10.5-9.el7.x86_64.rpm","okular-4.10.5-9.el7.x86_64.rpm","okular-devel-4.10.5-9.el7.x86_64.rpm"],"source":"okular-4.10.5-9.el7.src.rpm"},{"binary":["libssh2-devel-1.8.0-4.el7.x86_64.rpm","libssh2-1.8.0-4.el7.x86_64.rpm","libssh2-docs-1.8.0-4.el7.noarch.rpm"],"source":"libssh2-1.8.0-4.el7.src.rpm"}]}]}

CVE

参考