Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-0787

Опубликовано: 13 апр. 2016
Источник: debian
EPSS Низкий

Описание

The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libssh2fixed1.5.0-2.1package

Примечания

  • Upstream fix: https://github.com/libssh2/libssh2/commit/ca5222ea819cc5ed797860070b4c6c1aeeb28420

  • Upstream patch only fixes DH SHA-256 key exchange type, not DH SHA-1

EPSS

Процентиль: 84%
0.02297
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 9 лет назад

The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."

redhat
больше 9 лет назад

The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."

CVSS3: 5.9
nvd
больше 9 лет назад

The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."

suse-cvrf
больше 9 лет назад

Security update for libssh2_org

suse-cvrf
больше 9 лет назад

Security update for libssh2_org

EPSS

Процентиль: 84%
0.02297
Низкий