File _patchinfo of Package patchinfo
<patchinfo incident="4819">
<issue id="967026" tracker="bnc">CVE-2016-0787: libssh2_org: Weakness in diffie-hellman secret key generation</issue>
<issue id="961964" tracker="bnc">inconsistent KEX support of libssh2 and openSSH in SLES11 SP4</issue>
<issue id="933336" tracker="bnc">libssh2 bug causes curl scp problems on fips enabled hosts</issue>
<issue id="CVE-2016-0787" tracker="cve" />
<category>security</category>
<rating>moderate</rating>
<packager>vitezslav_cizek</packager>
<description>
This update for libssh2_org fixes the following issues:
Security issue fixed:
- CVE-2016-0787 (bsc#967026):
Weakness in diffie-hellman secret key generation lead to much shorter DH groups
then needed, which could be used to retrieve server keys.
A feature was added:
- Support of SHA256 digests for DH group exchanges was added (fate#320343, bsc#961964)
Bug fixed:
- Properly detect EVP_aes_128_ctr at configure time (bsc#933336)
This update was imported from the SUSE:SLE-12:Update update project.</description>
<summary>Security update for libssh2_org</summary>
</patchinfo>