Cyber Resilience
← All news

[UPDATE] [mittel] libssh: Mehrere Schwachstellen ermöglichen Manipulation von Dateien und DoS

Our takeCERT-Bund updated its advisory on multiple confirmed flaws in libssh that let an attacker tamper with files or cause denial of service. Update if you run it yourself (some enterprises); most smaller teams rely on managed SSH libraries and can ignore this one.
Sources (2)
What this means for you — Security leader:Update libssh to a fixed version if you self-host any software or containers that bundle it. The CERT-Bund update confirms file manipulation and DoS risks.
What this means for you — Lean IT orgs:Check whether any of your applications or devices use libssh. If they do and you can update them, do so; otherwise ask your vendor when a fix will be available.
What this means for you — MSP:Scan client environments for libssh usage (especially in Linux containers, network appliances, or custom apps). Apply the updated version where found; most clients without in-house development can ignore this one.
What this means for you — Researcher:CERT-Bund has updated its advisory on multiple confirmed vulnerabilities in libssh that allow file manipulation and denial of service.