ALT-PU-2014-1031-1
Closed vulnerabilities
                                                                                    Published: 2013-02-05
Modified: 2025-04-11
                                                                            Modified: 2025-04-11
CVE-2013-0176
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.
                                                                                        
                                                                                        
                                                                                            Severity: MEDIUM (4.3)
                                                                                        
                                                                                        
                                                                                        
                                                                                        
                                                                                            Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
                                                                                        
                                                                                        
                                                                                    
                                                                                References:
                                                                        - http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098065.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098094.html
- http://secunia.com/advisories/51982
- http://www.libssh.org/2013/01/22/libssh-0-5-4-security-release/
- http://www.ubuntu.com/usn/USN-1707-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81595
- http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098065.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098094.html
- http://secunia.com/advisories/51982
- http://www.libssh.org/2013/01/22/libssh-0-5-4-security-release/
- http://www.ubuntu.com/usn/USN-1707-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81595
