CVE-2016-0739
published 2016-04-13CVE-2016-0739: libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to…
PriorityP429medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
2.43%
82.4th percentile
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libssh | < libssh 0.6.3-4.3 (bookworm) | libssh 0.6.3-4.3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libssh | libssh | <= 0.7.2 | — |
| libssh | libssh | >= 0 < 0.6.3-4.3 | 0.6.3-4.3 |
| libssh | libssh | >= 0 < 0.6.3-4.3 | 0.6.3-4.3 |
| libssh | libssh | >= 0 < 0.6.3-4.3 | 0.6.3-4.3 |
| libssh | libssh | >= 0 < 0.6.3-4.3 | 0.6.3-4.3 |
| libssh | libssh | >= 0 < 0.6.1-0ubuntu3.3 | 0.6.1-0ubuntu3.3 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v7q8-7g48-2272: libssh before 0
ghsa_unreviewed·2022-05-17
CVE-2016-0739 [MEDIUM] CWE-200 GHSA-v7q8-7g48-2272: libssh before 0
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
OSV
CVE-2016-0739: libssh before 0
osv·2016-04-13·CVSS 5.9
CVE-2016-0739 [MEDIUM] CVE-2016-0739: libssh before 0
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
OSV
libssh vulnerabilities
osv·2016-02-23·CVSS 7.5
CVE-2015-3146 [HIGH] libssh vulnerabilities
libssh vulnerabilities
Mariusz Ziulek discovered that libssh incorrectly handled certain packets.
A remote attacker could possibly use this issue to cause libssh to crash,
resulting in a denial of service.
(CVE-2015-3146)
Aris Adamantiadis discovered that libssh incorrectly generated ephemeral
secret keys of 128 bits instead of the recommended 1024 or 2048 bits when
using the diffie-hellman-group1 and diffie-hellman-group14 methods. If a
remote attacker were able to perform a machine-in-the-middle attack, this flaw
could be exploited to view sensitive information. (CVE-2016-0739)
Red Hat
libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length
vendor_redhat·2016-02-23·CVSS 5.9
CVE-2016-0739 [MEDIUM] CWE-704 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length
libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
A type confusion issue was found in the way libssh generated ephemeral secrets for the diffie-hellman-group1 and diffie-hellman-group14 key exchange methods. This would cause an SSHv2 Diffie-Hellman handshake to use significantly less secure random parameters.
Ubuntu
libssh vulnerabilities
vendor_ubuntu·2016-02-23·CVSS 7.5
CVE-2015-3146 [HIGH] libssh vulnerabilities
Title: libssh vulnerabilities
Summary: Several security issues were fixed in libssh.
Mariusz Ziulek discovered that libssh incorrectly handled certain packets.
A remote attacker could possibly use this issue to cause libssh to crash,
resulting in a denial of service.
(CVE-2015-3146)
Aris Adamantiadis discovered that libssh incorrectly generated ephemeral
secret keys of 128 bits instead of the recommended 1024 or 2048 bits when
using the diffie-hellman-group1 and diffie-hellman-group14 methods. If a
remote attacker were able to perform a machine-in-the-middle attack, this flaw
could be exploited to view sensitive information. (CVE-2016-0739)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2016-0739: libssh - libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1)...
vendor_debian·2016·CVSS 5.9
CVE-2016-0739 [MEDIUM] CVE-2016-0739: libssh - libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1)...
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
Scope: local
bookworm: resolved (fixed in 0.6.3-4.3)
bullseye: resolved (fixed in 0.6.3-4.3)
forky: resolved (fixed in 0.6.3-4.3)
sid: resolved (fixed in 0.6.3-4.3)
trixie: resolved (fixed in 0.6.3-4.3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length [epel-all]
bugzilla·2016-02-23·CVSS 5.9
CVE-2016-0739 [MEDIUM] CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length [epel-all]
CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length [fedora-all]
bugzilla·2016-02-23·CVSS 5.9
CVE-2016-0739 [MEDIUM] CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length [fedora-all]
CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length [fedora-all]
bugzilla·2016-02-23·CVSS 5.9
CVE-2016-0739 [MEDIUM] CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length [fedora-all]
CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length [epel-all]
bugzilla·2016-02-23·CVSS 5.9
CVE-2016-0739 [MEDIUM] CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length [epel-all]
CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length
bugzilla·2016-02-09·CVSS 5.9
CVE-2016-0739 [MEDIUM] CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length
CVE-2016-0739 libssh: bits/bytes confusion resulting in truncated Difffie-Hellman secret length
Andreas Schneider of Red Hat reports:
Due to a byte/bit confusion, the DH secret was too short. This file was
completely reworked and will be commited in a future version.
This issue may be worked around by using other key exchange methods, such as
[email protected] or ecdh-sha2-nistp256, both are not vulnerable.
By default, an unpatched libssh implementation will already attempt to use
these two more secure methods when supported by the other party.
Discussion:
Created attachment 1122470
libssh-CVE-2016-0739.patch
---
The embargo is currently set for Feb 23rd, 2016 14:00 CET.
---
Created attachment 1128493
CVE-2016-0739 advisory text
---
Created attachment 1129246
Patch
T
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178058.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-March/178822.htmlhttp://lists.opensuse.org/opensuse-updates/2016-03/msg00111.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0566.htmlhttp://www.debian.org/security/2016/dsa-3488http://www.ubuntu.com/usn/USN-2912-1https://puppet.com/security/cve/CVE-2016-0739https://security.gentoo.org/glsa/201606-12https://www.libssh.org/2016/02/23/libssh-0-7-3-security-and-bugfix-release/https://www.libssh.org/security/advisories/CVE-2016-0739.txthttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/178058.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-March/178822.htmlhttp://lists.opensuse.org/opensuse-updates/2016-03/msg00111.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0566.htmlhttp://www.debian.org/security/2016/dsa-3488http://www.ubuntu.com/usn/USN-2912-1https://puppet.com/security/cve/CVE-2016-0739https://security.gentoo.org/glsa/201606-12https://www.libssh.org/2016/02/23/libssh-0-7-3-security-and-bugfix-release/https://www.libssh.org/security/advisories/CVE-2016-0739.txt
2016-04-13
Published