Skip to content

Conversation

@staticfloat
Copy link
Member

@staticfloat staticfloat commented Apr 17, 2019

LibSSH2 up to and including 1.8.0 has a serious vulnerability (https://nvd.nist.gov/vuln/detail/CVE-2019-3855). We should upgrade to LibSSH2 v1.8.1+ as soon as possible and give out new binaries on all channels.

@ararslan ararslan added the external dependencies Involves LLVM, OpenBLAS, or other linked libraries label Apr 17, 2019
@staticfloat staticfloat merged commit 1dc8236 into master Apr 18, 2019
@vchuravy vchuravy deleted the sf/libssh2_upgrade branch April 18, 2019 17:50
@KristofferC KristofferC mentioned this pull request Apr 19, 2019
39 tasks
staticfloat added a commit that referenced this pull request Apr 19, 2019
KristofferC pushed a commit that referenced this pull request Apr 20, 2019
@KristofferC KristofferC mentioned this pull request Apr 20, 2019
58 tasks
KristofferC pushed a commit that referenced this pull request Apr 20, 2019
@KristofferC KristofferC mentioned this pull request Aug 26, 2019
55 tasks
KristofferC pushed a commit that referenced this pull request Feb 20, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

external dependencies Involves LLVM, OpenBLAS, or other linked libraries

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants