OESA-2021-1312

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1312
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2021-1312.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2021-1312
Upstream
Published
2021-08-20T11:03:08Z
Modified
2025-08-12T05:08:07.496576Z
Summary
apache-sshd security update
Details

Apache SSHD is a 100% pure java library to support the SSH protocols on both the client and server side.

Security Fix(es):

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0(CVE-2021-30129)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/openEuler/apache-sshd&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.0-2.oe1

Ecosystem specific

{
    "src": [
        "apache-sshd-2.2.0-2.oe1.src.rpm"
    ],
    "noarch": [
        "apache-sshd-javadoc-2.2.0-2.oe1.noarch.rpm",
        "apache-sshd-2.2.0-2.oe1.noarch.rpm"
    ]
}

openEuler:20.03-LTS-SP2 / apache-sshd

Package

Name
apache-sshd
Purl
pkg:rpm/openEuler/apache-sshd&distro=openEuler-20.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.0-2.oe1

Ecosystem specific

{
    "src": [
        "apache-sshd-2.2.0-2.oe1.src.rpm"
    ],
    "noarch": [
        "apache-sshd-2.2.0-2.oe1.noarch.rpm",
        "apache-sshd-javadoc-2.2.0-2.oe1.noarch.rpm"
    ]
}