vulnerability

FreeBSD: VID-3d7dfd63-823b-11ea-b3a8-240a644dd835 (CVE-2020-1730): Client/server denial of service when handling AES-CTR ciphers

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Apr 19, 2020
Added
Apr 20, 2020
Modified
Dec 10, 2025

Description

The libssh team reports (originally reported by Yasheng Yang from Google): A malicious client or server could crash the counterpart implemented with libssh AES-CTR ciphers are used and don't get fully initialized. It will crash when it tries to cleanup the AES-CTR ciphers when closing the connection.

Solution

freebsd-upgrade-package-libssh
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.