CVE-2015-3146
published 2016-04-13CVE-2015-3146: The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote…
PriorityP337high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.91%
89.1th percentile
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted SSH packet.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libssh | < libssh 0.6.3-4.2 (bookworm) | libssh 0.6.3-4.2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libssh | libssh | <= 0.6.4 | — |
| libssh | libssh | >= 0 < 0.6.3-4.2 | 0.6.3-4.2 |
| libssh | libssh | >= 0 < 0.6.3-4.2 | 0.6.3-4.2 |
| libssh | libssh | >= 0 < 0.6.3-4.2 | 0.6.3-4.2 |
| libssh | libssh | >= 0 < 0.6.3-4.2 | 0.6.3-4.2 |
| libssh | libssh | >= 0 < 0.6.1-0ubuntu3.3 | 0.6.1-0ubuntu3.3 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-46jx-xcg7-prj7: The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb
ghsa_unreviewed·2022-05-17
CVE-2015-3146 [HIGH] GHSA-46jx-xcg7-prj7: The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted SSH packet.
OSV
CVE-2015-3146: The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb
osv·2016-04-13·CVSS 7.5
CVE-2015-3146 [HIGH] CVE-2015-3146: The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted SSH packet.
OSV
libssh vulnerabilities
osv·2016-02-23·CVSS 7.5
CVE-2015-3146 [HIGH] libssh vulnerabilities
libssh vulnerabilities
Mariusz Ziulek discovered that libssh incorrectly handled certain packets.
A remote attacker could possibly use this issue to cause libssh to crash,
resulting in a denial of service.
(CVE-2015-3146)
Aris Adamantiadis discovered that libssh incorrectly generated ephemeral
secret keys of 128 bits instead of the recommended 1024 or 2048 bits when
using the diffie-hellman-group1 and diffie-hellman-group14 methods. If a
remote attacker were able to perform a machine-in-the-middle attack, this flaw
could be exploited to view sensitive information. (CVE-2016-0739)
Ubuntu
libssh vulnerabilities
vendor_ubuntu·2016-02-23·CVSS 7.5
CVE-2015-3146 [HIGH] libssh vulnerabilities
Title: libssh vulnerabilities
Summary: Several security issues were fixed in libssh.
Mariusz Ziulek discovered that libssh incorrectly handled certain packets.
A remote attacker could possibly use this issue to cause libssh to crash,
resulting in a denial of service.
(CVE-2015-3146)
Aris Adamantiadis discovered that libssh incorrectly generated ephemeral
secret keys of 128 bits instead of the recommended 1024 or 2048 bits when
using the diffie-hellman-group1 and diffie-hellman-group14 methods. If a
remote attacker were able to perform a machine-in-the-middle attack, this flaw
could be exploited to view sensitive information. (CVE-2016-0739)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets
vendor_redhat·2015-04-30·CVSS 7.5
CVE-2015-3146 [HIGH] CWE-476 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets
libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted SSH packet.
Package: libssh (Red Hat Enterprise Linux Extended Update Support 7.1) - Affected
Debian
CVE-2015-3146: libssh - The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_c...
vendor_debian·2015·CVSS 7.5
CVE-2015-3146 [HIGH] CVE-2015-3146: libssh - The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_c...
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted SSH packet.
Scope: local
bookworm: resolved (fixed in 0.6.3-4.2)
bullseye: resolved (fixed in 0.6.3-4.2)
forky: resolved (fixed in 0.6.3-4.2)
sid: resolved (fixed in 0.6.3-4.2)
trixie: resolved (fixed in 0.6.3-4.2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets [fedora-all]
bugzilla·2015-05-04·CVSS 7.5
CVE-2015-3146 [HIGH] CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets [fedora-all]
CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets [epel-all]
bugzilla·2015-05-04·CVSS 7.5
CVE-2015-3146 [HIGH] CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets [epel-all]
CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg comm
Bugzilla
CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets
bugzilla·2015-04-21·CVSS 7.5
CVE-2015-3146 [HIGH] CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets
CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets
libssh versions 0.5.1 and above have a logical error in the handling of a
SSH_MSG_NEWKEYS and SSH_MSG_KEXDH_REPLY package. A detected error did not set
the session into the error state correctly and further processed the packet
which leads to a null pointer dereference. This is the packet after the initial
key exchange and doesn't require authentication.
Both client and server are are vulnerable, pre-authentication and pre-crypto
and and can be explointed with a MITM attack. This could be used for a
Denial of Service (DoS) attack.
Acknowledgements:
Red Hat would like to thank the libssh team for reporting this issue. The libssh team acknowledges Mariusz Ziu
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/161802.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158013.htmlhttp://www.debian.org/security/2016/dsa-3488http://www.ubuntu.com/usn/USN-2912-1https://git.libssh.org/projects/libssh.git/commit/?h=libssh-0.6.5&id=94f6955fbaee6fda9385a23e505497efe21f5b4fhttps://www.libssh.org/2015/04/30/libssh-0-6-5-security-and-bugfix-release/https://www.libssh.org/security/advisories/CVE-2015-3146.txthttp://lists.fedoraproject.org/pipermail/package-announce/2015-July/161802.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/158013.htmlhttp://www.debian.org/security/2016/dsa-3488http://www.ubuntu.com/usn/USN-2912-1https://git.libssh.org/projects/libssh.git/commit/?h=libssh-0.6.5&id=94f6955fbaee6fda9385a23e505497efe21f5b4fhttps://www.libssh.org/2015/04/30/libssh-0-6-5-security-and-bugfix-release/https://www.libssh.org/security/advisories/CVE-2015-3146.txt
2016-04-13
Published