Record summary

CVE-2013-0176 has a selected CVSS score of 4.3; EIP currently links 1 repository PoC.

Description

The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

Proofs of concept

1

Repository PoCs

GitLabyongchuank/cve-2013-0176-libssh-null-pointer-dereferenceRepository PoCby yongchuankStars: 0Not analyzed3 files

1.5 MiB

GitLab

PoC details

References

7