CVE-2015-1782: Input Validation
Published Mar 13, 2015
·Updated
The kexagreemethods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSHMSGKEXINIT packet.
Affected Software
5 affected components
Debian Debian Linux=7.0
libssh2 libssh2<=1.4.3
Fedoraproject Fedora=20
Fedoraproject Fedora=21
Fedoraproject Fedora=22
Event History
Mar 13, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1782?
CVE-2015-1782 has a severity rating of medium due to the potential denial of service it can cause.
2
How do I fix CVE-2015-1782?
To fix CVE-2015-1782, update libssh2 to version 1.5.0 or higher, or apply the relevant patches from your vendor.
3
What impact does CVE-2015-1782 have on affected systems?
CVE-2015-1782 can cause a denial of service by crashing the application when receiving specially crafted SSH_MSG_KEXINIT packets.
4
Which versions of libssh2 are affected by CVE-2015-1782?
CVE-2015-1782 affects libssh2 versions up to and including 1.4.3.
5
What systems are vulnerable to CVE-2015-1782?
Vulnerable systems include Debian 7.0 and Fedora versions 20, 21, and 22 that utilize affected versions of libssh2.