A flaw was found in libssh.
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
What happened
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
Does it affect you
Not enough information
No products recorded, so this cannot be matched against anything.
What to do
- Follow the vendor advisory for the fixed release and any interim mitigation.
access.redhat.com - Follow the vendor advisory for the fixed release and any interim mitigation.
access.redhat.com - Follow the vendor advisory for the fixed release and any interim mitigation.
bugzilla.redhat.com
Vendor's affected list
- rhel
- Exactly 8.0
Sources
A verdict here is derived from what you told us and what the vendor published. It is not an assessment of your environment. Why we never say you are safe.