cbcvebase.
CVE-2015-1782
published 2015-03-13

CVE-2015-1782: The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted…

PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.50%
87.9th percentile
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibssh2< libssh2 1.4.3-4.1 (bookworm)libssh2 1.4.3-4.1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
libssh2libssh2<= 1.4.3
libssh2libssh2>= 0 < 1.4.3-4.11.4.3-4.1
libssh2libssh2>= 0 < 1.4.3-4.11.4.3-4.1
libssh2libssh2>= 0 < 1.4.3-4.11.4.3-4.1
libssh2libssh2>= 0 < 1.4.3-4.11.4.3-4.1

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.