REDHAT-BUG-2498180: Medium severity libssh libssh (OpenSSL backend AES-GCM) vulnerability
A flaw was found in libssh builds using the OpenSSL backend for AES-GCM. In the decrypt path in src/libcrypto.c, the return value from EVPDecryptFinal() was checked incorrectly, so authentication tag verification failures were not handled as integrity failures. This could effectively remove integrity protection for affected AES-GCM sessions and allow an in-path attacker to modify plaintext on the wire without detection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2498180?
The severity of REDHAT-BUG-2498180 is rated as medium with a score of 4.
How do I fix REDHAT-BUG-2498180?
To fix REDHAT-BUG-2498180, update the affected packages of libssh and OpenSSL to the latest recommended versions.
What are the affected software versions for REDHAT-BUG-2498180?
The affected software versions for REDHAT-BUG-2498180 are libssh builds using the OpenSSL backend for AES-GCM.
What vulnerability does REDHAT-BUG-2498180 address?
REDHAT-BUG-2498180 addresses a flaw in the decryption process that leads to improper handling of authentication tag verification failures.
What impact does REDHAT-BUG-2498180 have on security?
The impact of REDHAT-BUG-2498180 is a potential integrity failure, which may expose sensitive data to unauthorized access.