| Type | URI |
|---|---|
| Issue Tracking | https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14889 |
| Third Party Advisory | https://usn.ubuntu.com/4219-1/ |
| Vendor Advisory | https://www.libssh.org/security/advisories/CVE-2019-14889.txt |
| Mailing List | http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00033.html |
| Mailing List | https://lists.debian.org/debian-lts-announce/2019/12/msg00020.html |
| Third Party Advisory | https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7JJWJTXVWLLJTVHBPGWL7472S5FWXYQR/ |
| Third Party Advisory | https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EV2ONSPDJCTDVORCB4UGRQUZQQ46JHRN/ |
| Mailing List | http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00047.html |
| Third Party Advisory | https://security.gentoo.org/glsa/202003-27 |
| Third Party Advisory | https://www.oracle.com/security-alerts/cpuapr2020.html |
| CPE URI | Source package | Min version | Max version |
|---|---|---|---|
cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* |
libssh | >= None | < 0.8.8 |
cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* |
libssh | >= 0.9.0 | < 0.9.3 |
| Source package | Branch | Version | Maintainer | Status |
|---|---|---|---|---|
| libssh | edge-community | 0.9.3-r0 | None | fixed |
| libssh | edge-community | 0.7.6-r0 | None | possibly vulnerable |
| libssh | 3.22-community | 0.9.3-r0 | None | fixed |
| libssh | 3.22-community | 0.7.6-r0 | None | possibly vulnerable |
| libssh | 3.21-community | 0.9.3-r0 | None | fixed |
| libssh | 3.20-community | 0.9.3-r0 | None | fixed |
| libssh | 3.19-community | 0.9.3-r0 | None | fixed |
| libssh | 3.18-community | 0.9.3-r0 | None | fixed |
| libssh | 3.17-community | 0.9.3-r0 | None | fixed |
| libssh | 3.11-main | 0.9.3-r0 | None | fixed |
| libssh | 3.10-main | 0.8.8-r0 | None | fixed |