First published: Tue Feb 05 2013(Updated: )
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libssh Libssh | <=0.5.3 | |
Libssh Libssh | =0.4.7 | |
Libssh Libssh | =0.4.8 | |
Libssh Libssh | =0.5.0 | |
Libssh Libssh | =0.5.0-rc1 | |
Libssh Libssh | =0.5.1 | |
Libssh Libssh | =0.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.