First published: Fri Jul 31 2020(Updated: )
libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL. External Reference: <a href="https://bugs.gentoo.org/734624">https://bugs.gentoo.org/734624</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1862456 is considered high due to the NULL pointer dereference vulnerability.
To fix REDHAT-BUG-1862456, update to the latest version of libssh that has addressed this issue.
REDHAT-BUG-1862456 affects libssh version 0.9.4.
Yes, a potential exploit for REDHAT-BUG-1862456 can lead to application crashes or denial of service.
REDHAT-BUG-1862456 was reported in October 2020.