CVE-2015-1782 — Improper Input Validation in Libssh2
Severity
6.8MEDIUMNVD
EPSS
4.1%
top 11.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 13
Latest updateMay 17
Description
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.
CVSS vector
AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4
Affected Packages2 packages
Also affects: Debian Linux 7.0, Fedora 20, 21, 22