CVE Vulnerabilities

CVE-2013-0176

Published: Feb 05, 2013 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a Client: Diffie-Hellman Key Exchange Init packet.

Affected Software

Name Vendor Start Version End Version
Libssh Libssh * 0.5.3 (including)
Libssh Libssh 0.4.7 (including) 0.4.7 (including)
Libssh Libssh 0.4.8 (including) 0.4.8 (including)
Libssh Libssh 0.5.0 (including) 0.5.0 (including)
Libssh Libssh 0.5.0-rc1 (including) 0.5.0-rc1 (including)
Libssh Libssh 0.5.1 (including) 0.5.1 (including)
Libssh Libssh 0.5.2 (including) 0.5.2 (including)
Libssh Ubuntu devel *
Libssh Ubuntu hardy *
Libssh Ubuntu lucid *
Libssh Ubuntu oneiric *
Libssh Ubuntu precise *
Libssh Ubuntu quantal *
Libssh Ubuntu upstream *

References