← Back

CVE-2020-1730

nvd nist
Published: Apr 13, 2020Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.

Affected (9)

Products: Libssh: Libssh · Canonical: Ubuntu Linux · Fedoraproject: Fedora · +3 more
Show all products
1 product
Libssh
1 product
Ubuntu Linux
1 product
Fedora
1 product
Cloud Backup
1 product
Enterprise Linux
1 product
Mysql Workbench
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Libssh
From 0.8.0 to 0.8.9
From 0.9.0 to 0.9.4
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 18.04
Version 19.10
Fedoraproject
Version 31
Version 32
All versions
Version 8.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.0.21

References (14)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.