[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Possible regression/problem with libssh2 update



Hi Mike

While working on an update for libssh2 first for buster and stretch
for the recent CVEs I noticed that the libssh2 update might have a
problem with one patch, when I compared with the jessie LTS update.

Upstream did wrongly apply some checks, which resulted
https://github.com/libssh2/libssh2/pull/327 .
Commit:
https://github.com/libssh2/libssh2/commit/165f05ef01a95538b426cc8c90da8accfaa20d01

I have included this commit in
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=924965#23

And actually a user followed up todayin the bug #924965.

Can you double check if 1.4.3-4.1+deb8u2 for this issue?

Regards,
Salvatore


Reply to: