cbcvebase.
CVE-2023-1667
published 2023-05-26

CVE-2023-1667: A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of…

PriorityP429medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.31%
67.5th percentile
A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibssh< libssh 0.10.5-1 (bookworm)libssh 0.10.5-1 (bookworm)
fedoraprojectfedora
libsshlibssh
libsshlibssh>= 0 < 0.9.7-0+deb11u10.9.7-0+deb11u1
libsshlibssh>= 0 < 0.10.5-10.10.5-1
libsshlibssh>= 0 < 0.10.5-10.10.5-1
libsshlibssh>= 0 < 0.10.5-10.10.5-1
libsshlibssh>= 0 < 0.9.3-2ubuntu2.30.9.3-2ubuntu2.3
libsshlibssh>= 0 < 0.9.6-2ubuntu0.22.04.10.9.6-2ubuntu0.22.04.1
libsshlibssh0.10.0 – 0.10.4
libsshlibssh0.9.1 – 0.9.6
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.