Description
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9Confidentiality: None
Integrity: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-mwpj-rq8j-724c: The publickey_from_privatekey function in libssh before 0↗2022-05-05 ▶ CVEListCVE-2013-0176: The publickey_from_privatekey function in libssh before 0↗2013-02-05 ▶ OSVCVE-2013-0176: The publickey_from_privatekey function in libssh before 0↗2013-02-05 ▶ 📋Vendor Advisories
2Ubuntulibssh vulnerability↗2013-01-28 ▶ DebianCVE-2013-0176: libssh - The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm...↗2013 ▶ 💬Community
2BugzillaCVE-2013-0176 libssh: NULL dereference leads to denial of service [fedora-all]↗2013-01-22 ▶ BugzillaCVE-2013-0176 libssh: NULL dereference leads to denial of service↗2013-01-11 ▶