CVE-2012-4561Libssh vulnerability

8 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
3.7%
top 12.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 30
Latest updateMay 17

Description

The (1) publickey_make_dss, (2) publickey_make_rsa, (3) signature_from_string, (4) ssh_do_sign, and (5) ssh_sign_session_id functions in keys.c in libssh before 0.5.3 free "an invalid pointer on an error path," which might allow remote attackers to cause a denial of service (crash) via unspecified vectors.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianlibssh/libssh< 0.5.3-1+3
NVDlibssh/libssh0.5.2+4

🔴Vulnerability Details

3
GHSA
GHSA-m2v7-9rhw-324g: The (1) publickey_make_dss, (2) publickey_make_rsa, (3) signature_from_string, (4) ssh_do_sign, and (5) ssh_sign_session_id functions in keys2022-05-17
OSV
CVE-2012-4561: The (1) publickey_make_dss, (2) publickey_make_rsa, (3) signature_from_string, (4) ssh_do_sign, and (5) ssh_sign_session_id functions in keys2012-11-30
CVEList
CVE-2012-4561: The (1) publickey_make_dss, (2) publickey_make_rsa, (3) signature_from_string, (4) ssh_do_sign, and (5) ssh_sign_session_id functions in keys2012-11-30

📋Vendor Advisories

2
Ubuntu
libssh vulnerabilities2012-11-26
Debian
CVE-2012-4561: libssh - The (1) publickey_make_dss, (2) publickey_make_rsa, (3) signature_from_string, (...2012

💬Community

2
Bugzilla
CVE-2012-4559 CVE-2012-4560 CVE-2012-4561 CVE-2012-4562 libssh various flaws [fedora-all]2012-11-20
Bugzilla
CVE-2012-4561 libssh: multiple invalid free() flaws2012-10-30