Bugzilla – Bug 802631
VUL-1: CVE-2013-0176: libssh: remote denial of service in DH key exchange
Last modified: 2019-12-05 23:39:01 UTC
is public, via CVE db CVE-2013-0176 The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereferen ce and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet. Reference: CONFIRM: http://www.libssh.org/2013/01/22/libssh-0-5-4-security-release/ Reference: UBUNTU: http://www.ubuntu.com/usn/USN-1707-1 Reference: FEDORA: http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098094.html Reference: FEDORA: http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098065.html
cc Jim, need to clarify what SLE libssh versions are affected too9.
bugbot adjusting priority