CVE-2012-6063: Double Free
Published Nov 30, 2012
·Updated
Double free vulnerability in the sftpmkdir function in sftp.c in libssh before 0.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors, a different vector than CVE-2012-4559.
Affected Software
6 affected components
libssh libssh<=0.5.2
libssh libssh=0.4.7
libssh libssh=0.4.8
libssh libssh=0.5.0
libssh libssh=0.5.0-rc1
libssh libssh=0.5.1
Event History
Nov 30, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6063?
CVE-2012-6063 has a CVSS score indicating a moderate severity due to its potential for denial of service and arbitrary code execution.
2
How do I fix CVE-2012-6063?
To fix CVE-2012-6063, upgrade to libssh version 0.5.3 or later.
3
What versions of libssh are affected by CVE-2012-6063?
CVE-2012-6063 affects libssh versions prior to 0.5.3, including 0.4.7, 0.4.8, 0.5.0, 0.5.0-rc1, and 0.5.1.
4
What kind of vulnerability is CVE-2012-6063?
CVE-2012-6063 is a double free vulnerability in the sftp_mkdir function.
5
Can CVE-2012-6063 be exploited remotely?
Yes, CVE-2012-6063 can be exploited by remote attackers to cause a denial of service.