Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jpg-fr24-wpvf

Опубликовано: 26 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 2.2

Описание

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the match_pattern() function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the match_pattern() function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.

EPSS

Процентиль: 20%
0.00066
Низкий

2.2 Low

CVSS3

Дефекты

CWE-1333

Связанные уязвимости

ubuntu
около 2 месяцев назад

[Denial of Service via inefficient regular expression processing]

CVSS3: 2.2
redhat
около 2 месяцев назад

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion, resulting in a Denial of Service (DoS) for the client.

debian

[Denial of Service via inefficient regular expression processing]

suse-cvrf
27 дней назад

Security update for libssh

suse-cvrf
27 дней назад

Security update for libssh

EPSS

Процентиль: 20%
0.00066
Низкий

2.2 Low

CVSS3

Дефекты

CWE-1333