FEDORA-2013-1422Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098065.html CVE-2013-0176
Record summary
CVE-2013-0176 has a selected CVSS score of 4.3; EIP currently links 1 repository PoC.
Description
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
Proofs of concept
1Repository PoCs
GitLabyongchuank/cve-2013-0176-libssh-null-pointer-dereferenceRepository PoCby yongchuankStars: 0Not analyzed3 files
References
7FEDORA-2013-1407Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098094.html 51982Third-party advisory
http://secunia.com/advisories/51982 libssh.orgConfirmation
http://www.libssh.org/2013/01/22/libssh-0-5-4-security-release USN-1707-1Vendor advisory
http://www.ubuntu.com/usn/USN-1707-1 libssh-publickeyfromprivatekey-dos(81595)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/81595 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-0176