CVE Vulnerabilities

CVE-2023-1667

NULL Pointer Dereference

Published: May 26, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
4.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Libssh Libssh 0.9.1 (including) 0.9.6 (including)
Libssh Libssh 0.10.0 (including) 0.10.4 (including)
Red Hat Enterprise Linux 8 RedHat libssh-0:0.9.6-10.el8_8 *
Red Hat Enterprise Linux 8 RedHat libssh-0:0.9.6-10.el8_8 *
Red Hat Enterprise Linux 8.6 Extended Update Support RedHat libssh-0:0.9.6-4.el8_6 *
Red Hat Enterprise Linux 9 RedHat libssh-0:0.10.4-11.el9 *
Red Hat Enterprise Linux 9 RedHat libssh-0:0.10.4-11.el9 *
Libssh Ubuntu bionic *
Libssh Ubuntu devel *
Libssh Ubuntu esm-infra/bionic *
Libssh Ubuntu esm-infra/focal *
Libssh Ubuntu esm-infra/xenial *
Libssh Ubuntu focal *
Libssh Ubuntu jammy *
Libssh Ubuntu kinetic *
Libssh Ubuntu lunar *
Libssh Ubuntu mantic *
Libssh Ubuntu noble *
Libssh Ubuntu oracular *
Libssh Ubuntu plucky *
Libssh Ubuntu trusty *
Libssh Ubuntu upstream *
Libssh Ubuntu xenial *

Potential Mitigations

References