CVE Vulnerabilities

CVE-2012-4561

Published: Nov 30, 2012 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

The (1) publickey_make_dss, (2) publickey_make_rsa, (3) signature_from_string, (4) ssh_do_sign, and (5) ssh_sign_session_id functions in keys.c in libssh before 0.5.3 free an invalid pointer on an error path, which might allow remote attackers to cause a denial of service (crash) via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Libssh Libssh * 0.5.2 (including)
Libssh Libssh 0.4.7 (including) 0.4.7 (including)
Libssh Libssh 0.4.8 (including) 0.4.8 (including)
Libssh Libssh 0.5.0 (including) 0.5.0 (including)
Libssh Libssh 0.5.0-rc1 (including) 0.5.0-rc1 (including)
Libssh Libssh 0.5.1 (including) 0.5.1 (including)
Libssh Ubuntu hardy *
Libssh Ubuntu lucid *
Libssh Ubuntu oneiric *
Libssh Ubuntu precise *
Libssh Ubuntu quantal *
Libssh Ubuntu upstream *

References