{"schema_version":"1.7.3","id":"SUSE-SU-2024:0543-1","published":"2024-02-20T15:04:50Z","modified":"2026-02-04T04:21:26.774640Z","related":["CVE-2023-48795"],"upstream":["CVE-2023-48795"],"summary":"Security update for libssh2_org","details":"This update for libssh2_org fixes the following issues:\n\n- Always add the KEX pseudo-methods 'ext-info-c' and 'kex-strict-c-v00@openssh.com'\n  when configuring custom method list. [bsc#1218971, CVE-2023-48795]\n\n  * The strict-kex extension is announced in the list of available\n    KEX methods. However, when the default KEX method list is modified\n    or replaced, the extension is not added back automatically.\n","affected":[{"package":{"name":"libssh2_org","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/libssh2_org&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.0-29.12.1"}]}],"ecosystem_specific":{"binaries":[{"libssh2-devel":"1.11.0-29.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0543-1.json"}},{"package":{"name":"libssh2_org","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/libssh2_org&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.0-29.12.1"}]}],"ecosystem_specific":{"binaries":[{"libssh2-1":"1.11.0-29.12.1","libssh2-1-32bit":"1.11.0-29.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0543-1.json"}},{"package":{"name":"libssh2_org","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/libssh2_org&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.0-29.12.1"}]}],"ecosystem_specific":{"binaries":[{"libssh2-1":"1.11.0-29.12.1","libssh2-1-32bit":"1.11.0-29.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0543-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20240543-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218971"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-48795"}]}