Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jpg-fr24-wpvf

Опубликовано: 26 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 2.2

Описание

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the match_pattern() function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the match_pattern() function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.

EPSS

Процентиль: 13%
0.00223
Низкий

2.2 Low

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.

CVSS3: 2.2
redhat
6 месяцев назад

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.

CVSS3: 5.5
nvd
4 месяца назад

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.

CVSS3: 2.2
msrc
4 месяца назад

Libssh: libssh: denial of service via inefficient regular expression processing

CVSS3: 5.5
debian
4 месяца назад

A flaw was found in libssh. A remote attacker, by controlling client c ...

EPSS

Процентиль: 13%
0.00223
Низкий

2.2 Low

CVSS3

Дефекты

CWE-1333