← Back

CVE-2013-0176

nvd nist
Published: Feb 5, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.

Affected (7)

Products: Libssh: Libssh
1 product
Libssh
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Libssh
Up to 0.5.3
Version 0.4.7
Version 0.4.8
Version 0.5.0
Version 0.5.0 rc1
Version 0.5.1
Version 0.5.2

Related CWEs

References (12)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.