CVE-2013-0176
published 2013-02-05CVE-2013-0176: The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.05%
86.2th percentile
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libssh | < libssh 0.5.4-1 (bookworm) | libssh 0.5.4-1 (bookworm) |
| libssh | libssh | <= 0.5.3 | — |
| libssh | libssh | — | — |
| libssh | libssh | — | — |
| libssh | libssh | — | — |
| libssh | libssh | — | — |
| libssh | libssh | — | — |
| libssh | libssh | >= 0 < 0.5.4-1 | 0.5.4-1 |
| libssh | libssh | >= 0 < 0.5.4-1 | 0.5.4-1 |
| libssh | libssh | >= 0 < 0.5.4-1 | 0.5.4-1 |
| libssh | libssh | >= 0 < 0.5.4-1 | 0.5.4-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libssh vulnerability
vendor_ubuntu·2013-01-28
CVE-2013-0176 libssh vulnerability
Title: libssh vulnerability
Summary: libssh could be made to crash if it received specially crafted network
traffic.
Yong Chuan Koh discovered that libssh incorrectly handled certain
negotiation requests. A remote attacker could use this to cause libssh to
crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2013-0176: libssh - The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm...
vendor_debian·2013·CVSS 4.3
CVE-2013-0176 [MEDIUM] CVE-2013-0176: libssh - The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm...
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.
Scope: local
bookworm: resolved (fixed in 0.5.4-1)
bullseye: resolved (fixed in 0.5.4-1)
forky: resolved (fixed in 0.5.4-1)
sid: resolved (fixed in 0.5.4-1)
trixie: resolved (fixed in 0.5.4-1)
GHSA
GHSA-mwpj-rq8j-724c: The publickey_from_privatekey function in libssh before 0
ghsa_unreviewed·2022-05-05
CVE-2013-0176 [MEDIUM] GHSA-mwpj-rq8j-724c: The publickey_from_privatekey function in libssh before 0
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.
OSV
CVE-2013-0176: The publickey_from_privatekey function in libssh before 0
osv·2013-02-05·CVSS 4.3
CVE-2013-0176 [MEDIUM] CVE-2013-0176: The publickey_from_privatekey function in libssh before 0
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0176 libssh: NULL dereference leads to denial of service [fedora-all]
bugzilla·2013-01-22·CVSS 4.3
CVE-2013-0176 [MEDIUM] CVE-2013-0176 libssh: NULL dereference leads to denial of service [fedora-all]
CVE-2013-0176 libssh: NULL dereference leads to denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue af
Bugzilla
CVE-2013-0176 libssh: NULL dereference leads to denial of service
bugzilla·2013-01-11·CVSS 4.3
CVE-2013-0176 [MEDIUM] CVE-2013-0176 libssh: NULL dereference leads to denial of service
CVE-2013-0176 libssh: NULL dereference leads to denial of service
A NULL dereference was found in libssh 0.5.3's publickey_from_privatekey() function. When a server using libssh receives a "Client: Key Exchange Init", the server sets up the session and tries to set the algorithms by matching what the user specified vs what is supported in crypt_set_algorithms_server(). If there is no match, it will lead to a NULL dereference when receiving the "Client: Diffie-Hellman Key Exchange Init" packet, which will cause the program using libssh to crash.
Discussion:
Created attachment 678235
Patch for CVE-2013-0176
---
http://www.libssh.org/2013/01/22/libssh-0-5-4-security-release/
---
Fedora bugs are created automatically?
---
Created libssh tracking bugs for this issue
Affects: fedora-al
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098065.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098094.htmlhttp://secunia.com/advisories/51982http://www.libssh.org/2013/01/22/libssh-0-5-4-security-release/http://www.ubuntu.com/usn/USN-1707-1https://exchange.xforce.ibmcloud.com/vulnerabilities/81595http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098065.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098094.htmlhttp://secunia.com/advisories/51982http://www.libssh.org/2013/01/22/libssh-0-5-4-security-release/http://www.ubuntu.com/usn/USN-1707-1https://exchange.xforce.ibmcloud.com/vulnerabilities/81595
2013-02-05
Published