The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libssh2 | Jul 30, 2024 | Mar 13, 2015 |
| Freebsd | — | Upgrade libssh2 | Dec 10, 2025 | Sep 22, 2015 |
| Oracle Solaris | — | Upgrade library/libssh2 to version 1.7.0-0.175.3.14.0.4.0 on Solaris 11.3 | May 29, 2017 | Mar 13, 2015 |
| Oracle_linux | — | Upgrade libssh2-develUpgrade libssh2Upgrade libssh2-docs | Oct 16, 2024 | Mar 13, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 11, 2015 |
| Suse | — | Upgrade libssh2-1-x86Upgrade libssh2-develUpgrade libssh2-1-32bitUpgrade libssh2-1 | Dec 18, 2015 | Mar 13, 2015 |
| Ubuntu | — | Upgrade libssh2 | Nov 19, 2024 | Mar 13, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub