CVE-2020-1730
published 2020-04-13CVE-2020-1730: A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
3.06%
86.2th percentile
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libssh | < libssh 0.9.4-1 (bookworm) | libssh 0.9.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libssh | libssh | >= 0 < 0.9.4-1 | 0.9.4-1 |
| libssh | libssh | >= 0 < 0.9.4-1 | 0.9.4-1 |
| libssh | libssh | >= 0 < 0.9.4-1 | 0.9.4-1 |
| libssh | libssh | >= 0 < 0.9.4-1 | 0.9.4-1 |
| libssh | libssh | >= 0.8.0 < 0.8.9 | 0.8.9 |
| libssh | libssh | >= 0.9.0 < 0.9.4 | 0.9.4 |
| oracle | mysql_workbench | <= 8.0.21 | — |
| red_hat | libssh | — | — |
| red_hat | libssh | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle MySQL Risk Matrix: MySQL Workbench (libssh) — CVE-2020-1730
vendor_oracle·2020-10-15·CVSS 5.3
CVE-2020-1730 [MEDIUM] Oracle Oracle MySQL Risk Matrix: MySQL Workbench (libssh) — CVE-2020-1730
Oracle Oracle MySQL Risk Matrix: MySQL Workbench (libssh) vulnerability
CVE: CVE-2020-1730
CVSS: 5.3
Protocol: MySQL Workbench
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Red Hat
libssh: denial of service when handling AES-CTR (or DES) ciphers
vendor_redhat·2020-04-09·CVSS 5.3
CVE-2020-1730 [MEDIUM] CWE-476 libssh: denial of service when handling AES-CTR (or DES) ciphers
libssh: denial of service when handling AES-CTR (or DES) ciphers
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.
A flaw was found in the way libssh handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.
Mitigation: Disable AES-CTR ciphers (and DES in libssh 0.8). If y
Ubuntu
libssh vulnerability
vendor_ubuntu·2020-04-09
CVE-2020-1730 libssh vulnerability
Title: libssh vulnerability
Summary: libssh could be made to crash if it received specially crafted network
traffic.
Yasheng Yang discovered that libssh incorrectly handled AES-CTR ciphers. A
remote attacker could possibly use this issue to cause libssh to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-1730: libssh - A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it ...
vendor_debian·2020·CVSS 5.3
CVE-2020-1730 [MEDIUM] CVE-2020-1730: libssh - A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it ...
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.
Scope: local
bookworm: resolved (fixed in 0.9.4-1)
bullseye: resolved (fixed in 0.9.4-1)
forky: resolved (fixed in 0.9.4-1)
sid: resolved (fixed in 0.9.4-1)
trixie: resolved (fixed in 0.9.4-1)
GHSA
GHSA-6rh3-m266-5m77: A flaw was found in libssh versions before 0
ghsa_unreviewed·2022-05-24
CVE-2020-1730 [MEDIUM] CWE-476 GHSA-6rh3-m266-5m77: A flaw was found in libssh versions before 0
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.
OSV
CVE-2020-1730: A flaw was found in libssh versions before 0
osv·2020-04-13·CVSS 5.3
CVE-2020-1730 [MEDIUM] CVE-2020-1730: A flaw was found in libssh versions before 0
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27765 ImageMagick: division by zero at MagickCore/segment.c
bugzilla·2020-11-04·CVSS 3.3
CVE-2020-27765 [LOW] CVE-2020-27765 ImageMagick: division by zero at MagickCore/segment.c
CVE-2020-27765 ImageMagick: division by zero at MagickCore/segment.c
In ImageMagick, there is a Divisoin by Zero at MagickCore/segment.c.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1730
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/a4c89f2a61069ad7637bc7749cc1a839de442526
Discussion:
Acknowledgments:
Name: Suhwan Song (Seoul National University)
---
Statement:
This flaw is out of support scope for Red Hat Enterprise Linux 5, 6, and 7. Inkscape is not affected because it no longer uses a bundled ImageMagick in Red Hat Enterprise Linux 8. For more information regarding support scopes, please see https://access.redhat.com/support/policy/updates/errata .
---
Created ImageMagick tracking bugs for this issue:
Affects: epel-8 [bug 1901275]
Affects
Bugzilla
CVE-2020-1730 libssh: denial of service when handling AES-CTR (or DES) ciphers [fedora-all]
bugzilla·2020-04-09·CVSS 5.3
CVE-2020-1730 [MEDIUM] CVE-2020-1730 libssh: denial of service when handling AES-CTR (or DES) ciphers [fedora-all]
CVE-2020-1730 libssh: denial of service when handling AES-CTR (or DES) ciphers [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2020-1730 libssh: denial of service when handling AES-CTR (or DES) ciphers
bugzilla·2020-02-12·CVSS 5.3
CVE-2020-1730 [MEDIUM] CVE-2020-1730 libssh: denial of service when handling AES-CTR (or DES) ciphers
CVE-2020-1730 libssh: denial of service when handling AES-CTR (or DES) ciphers
A vulnerability was found in libssh through version 0.8.0, where a malicious client or server could crash the counterpart implemented with libssh AES-CTR ciphers are used and don't get fully initialized. It will crash when it tries to cleanup the AES-CTR ciphers when closing the connection.
Discussion:
Acknowledgments:
Name: libssh team
Upstream: Yasheng Yang (Google)
---
Mitigation:
Disable AES-CTR ciphers (and DES in libssh 0.8). If you implement a server using libssh we advise to use a prefork model so each session runs in an own process. If you have implemented your server this way this is not really an issue. The client will kill its own connection.
---
External References:
https://www.libssh.org/
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1730https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2A7BIFKUYIYKTY7FX4BEWVC2OHS5DPOU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VLSWHBQ3EPKGTGLQNH554Z746BJ3C554/https://security.netapp.com/advisory/ntap-20200424-0001/https://usn.ubuntu.com/4327-1/https://www.libssh.org/security/advisories/CVE-2020-1730.txthttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1730https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2A7BIFKUYIYKTY7FX4BEWVC2OHS5DPOU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VLSWHBQ3EPKGTGLQNH554Z746BJ3C554/https://security.netapp.com/advisory/ntap-20200424-0001/https://usn.ubuntu.com/4327-1/https://www.libssh.org/security/advisories/CVE-2020-1730.txthttps://www.oracle.com/security-alerts/cpuoct2020.html
2020-04-13
Published