-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 01 Aug 2026 13:42:11 +0200
Source: libssh
Binary: libssh-doc
Architecture: all
Version: 0.11.5-0+deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: all Build Daemon (x86-grnet-02) <buildd_all-x86-grnet-02@buildd.debian.org>
Changed-By: Martin Pitt <mpitt@debian.org>
Description:
 libssh-doc - tiny C SSH library - Documentation files
Closes: 1127693 1142537
Changes:
 libssh (0.11.5-0+deb13u1) trixie-security; urgency=medium
 .
   * New upstream security/bug fix release 0.11.4:
     - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request()
     - CVE-2026-0965: Possible Denial of Service when parsing unexpected
       configuration files
     - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input
     - CVE-2026-0967: Specially crafted patterns could cause DoS
     - CVE-2026-0968: OOB Read in sftp_parse_longname()
     - CVE-2026-3731: Read buffer overrun when handling SFTP extensions
     - Note: CVE-2025-14821 is Windows specific, does not apply to Linux
     https://www.libssh.org/2026/02/10/libssh-0-12-0-and-0-11-4-security-releases/
     (Closes: #1127693)
   * New upstream security/bug fix release 0.11.5:
     - CVE-2026-15370: Stack buffer overflow in SFTP server longname
       construction
     - CVE-2026-59843: Denial of service via zero advertised channel packet
       size
     - CVE-2026-59844: Denial of service via oversized SFTP read length
     - CVE-2026-59845: Denial of service via unchecked ProxyCommand fork()
       failure
     - CVE-2026-59846: Information disclosure via ProxyCommand %r username
       expansion
     - CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification
     - CVE-2026-59848: Denial of service via SFTP responses with unknown
       request IDs
     - CVE-2026-59849: Denial of service via automatic certificate
       authentication loop
     - CVE-2026-59850: Use-after-free via data callbacks on closed channels
     - Zero-initialize every ssh_string
     https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
     (Closes: #1142537)
Checksums-Sha1:
 6343e8a67bcf248be863d937c6966e64eea27bb1 615120 libssh-doc_0.11.5-0+deb13u1_all.deb
 245a488bec89936fe48a7aefed39fee283a5c96b 10432 libssh_0.11.5-0+deb13u1_all-buildd.buildinfo
Checksums-Sha256:
 445ca323060b5564507c1d63d8bf2b443cfb9291df4f604b67d23168e809e034 615120 libssh-doc_0.11.5-0+deb13u1_all.deb
 237f7ebd4aaa8efdf4207005d49e9ef586524fcdcc37d557d93371a8612c825e 10432 libssh_0.11.5-0+deb13u1_all-buildd.buildinfo
Files:
 cb8fd155eaf32ad85adb6f4c60ddd2cc 615120 doc optional libssh-doc_0.11.5-0+deb13u1_all.deb
 3563df89a8d7672a2eadb8f3196828d1 10432 libs optional libssh_0.11.5-0+deb13u1_all-buildd.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE81O8NL+3kjBAqEvLmgPNRvTf/zcFAmpuT/UACgkQmgPNRvTf
/zf7zRAAwQIY/jkxIFD5SHtmWjfxANwsO0ZXm4UkuGI8nY+iBA0vu+ZAz+qMuE09
/fZeYfn9MSKY7c6MPFtKuzz52aNMFVYZ+NeusZFmkrkVmnj7Uiwa2psGq52VJ4+7
YVHavlWgSE7cSVaWgEOuGEoaRsQLeRBP7HYbEFgLFeUPxynO+DBA9IKSqdcxCf9t
XQfAIy3gqFZja9Qf4M67kKI4RimmUGo1V9iktqUMFlgjB4KqtuEvztANxphrhjAF
+2bBqAxCfnxKnNaub9eTn/Onrj5dY6MQl46/MXVRCd8f4/Q+U+hzpAm+VneLnN/P
GhKbzb7NfZPyPmFWhyQYLSKSkX14ujInTvE8SVgSsaqbT+ACEyPVeighYSif3WRB
0Tn2LQCNa6xemb81fRAiGqXCP2mDU5blVG+hLWxGMbWwsZg5OkmyXwilkwJVa7KA
0zL0B1phb1TIXyw7lIY5cqD7NSd5d4cvigRmr8/km8CAajxcfMTxuMCn3NIHNQVe
N4U7voxqKsa0G8pqHtomJ39+HduWlnnJ/IVi0Zini0yV+rjUWulJG6Bi/T28IOXT
gb/JfV5RxgMpsszkR4Y9Xx9Tx7o9N/3MnsxGJIJgjbJJFlyRaE2BGxSo1gX4ltdS
ij6zqnzccAjoNeI4PYJLUsR68Lvq9xPbBFJRFK4HtSHYYnmNVfE=
=pltT
-----END PGP SIGNATURE-----
