CVE-2013-0176Libssh vulnerability

CWE-3998 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
1.0%
top 22.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 5
Latest updateMay 5

Description

The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debianlibssh/libssh< 0.5.4-1+3
NVDlibssh/libssh0.5.3+5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mwpj-rq8j-724c: The publickey_from_privatekey function in libssh before 02022-05-05
CVEList
CVE-2013-0176: The publickey_from_privatekey function in libssh before 02013-02-05
OSV
CVE-2013-0176: The publickey_from_privatekey function in libssh before 02013-02-05

📋Vendor Advisories

2
Ubuntu
libssh vulnerability2013-01-28
Debian
CVE-2013-0176: libssh - The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm...2013

💬Community

2
Bugzilla
CVE-2013-0176 libssh: NULL dereference leads to denial of service [fedora-all]2013-01-22
Bugzilla
CVE-2013-0176 libssh: NULL dereference leads to denial of service2013-01-11