cbcvebase.
CVE-2023-1667
published 2023-05-26

CVE-2023-1667: A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibssh< libssh 0.10.5-1 (bookworm)libssh 0.10.5-1 (bookworm)
fedoraprojectfedora
libsshlibssh
libsshlibssh>= 0 < 0.9.7-0+deb11u10.9.7-0+deb11u1
libsshlibssh>= 0 < 0.10.5-10.10.5-1
libsshlibssh>= 0 < 0.10.5-10.10.5-1
libsshlibssh>= 0 < 0.10.5-10.10.5-1
libsshlibssh>= 0 < 0.9.3-2ubuntu2.30.9.3-2ubuntu2.3
libsshlibssh>= 0 < 0.9.6-2ubuntu0.22.04.10.9.6-2ubuntu0.22.04.1
libsshlibssh0.10.0 – 0.10.4
libsshlibssh0.9.1 – 0.9.6
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM