PT-2015-6077 · Libssh+3 · Libssh+3

Mariusz Ziulek

·

Publicado

2015-05-05

·

Atualizado

2024-06-15

·

CVE-2015-3146

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libssh versions prior to 0.6.5
Description The issue is related to the improper validation of state in the SSH MSG NEWKEYS and SSH MSG KEXDH REPLY packet handlers. This allows remote attackers to cause a denial of service, resulting in a NULL pointer dereference and crash, via a crafted SSH packet.
Recommendations For versions prior to 0.6.5, update to version 0.6.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the SSH service to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2015-1549
CVE-2015-3146
DSA-3488-1
MGASA-2015-0209
OPENSUSE-SU-2024:10036-1
SUSE-SU-2015:1707-1
SUSE-SU-2015:1707-2
SUSE-SU-2015_1707-2
USN-2912-1

Produtos afetados

Alt Linux
Suse
Ubuntu
Libssh