cbcvebase.
CVE-2023-2283
published 2023-05-26

CVE-2023-2283: A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in…

PriorityP431medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.06%
60.8th percentile
A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the return value `rc,` which is initialized to SSH_ERROR and later rewritten to save the return value of the function call `pki_key_check_hash_compatible.` The value of the variable is not changed between this point and the cryptographic verification. Therefore any error between them calls `goto error` returning SSH_OK.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlibssh< libssh 0.10.5-1 (bookworm)libssh 0.10.5-1 (bookworm)
fedoraprojectfedora
libsshlibssh
libsshlibssh>= 0 < 0.9.7-0+deb11u10.9.7-0+deb11u1
libsshlibssh>= 0 < 0.10.5-10.10.5-1
libsshlibssh>= 0 < 0.10.5-10.10.5-1
libsshlibssh>= 0 < 0.10.5-10.10.5-1
libsshlibssh>= 0 < 0.9.3-2ubuntu2.30.9.3-2ubuntu2.3
libsshlibssh>= 0 < 0.9.6-2ubuntu0.22.04.10.9.6-2ubuntu0.22.04.1
libsshlibssh0.10.0 – 0.10.4
libsshlibssh0.9.1 – 0.9.6
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.