CVE-2008-0852: Null Pointer Dereference
Published Feb 21, 2008
·Updated
freeSSHd 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a SSH2MSGNEWKEYS packet to TCP port 22, which triggers a NULL pointer dereference.
Affected Software
1 affected component
FreeSSHd freeSSHd<=1.2
Event History
Feb 21, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0852?
CVE-2008-0852 has a high severity level as it can lead to a denial of service by crashing the service.
2
How do I fix CVE-2008-0852?
To fix CVE-2008-0852, upgrade to a version of FreeSSHd later than 1.2 which addresses the vulnerability.
3
What type of attack does CVE-2008-0852 exploit?
CVE-2008-0852 exploits a vulnerability through a specially crafted SSH2_MSG_NEWKEYS packet.
4
Which versions of FreeSSHd are affected by CVE-2008-0852?
CVE-2008-0852 affects FreeSSHd version 1.2 and earlier.
5
What impact does CVE-2008-0852 have on systems?
The impact of CVE-2008-0852 is a crash of the FreeSSHd service, leading to temporary unavailability.