Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libssh | Jul 30, 2024 | Dec 29, 2014 |
| Gentoo Linux | — | Upgrade net-libs/libssh.Upgrade net-libs/libssh2. | Oct 30, 2017 | Dec 28, 2014 |
| Suse | — | Upgrade libssh-devel-docUpgrade libssh-develUpgrade libssh4Upgrade libssh4-32bit | Dec 18, 2015 | Dec 28, 2014 |
| Ubuntu | — | Upgrade libssh-4 | Nov 8, 2024 | Dec 29, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub