Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-5449

Опубликовано: 25 июл. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads to failed memory allocation and causes the server process to crash, resulting in a denial of service.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:libssh:libssh:0.11.0:*:*:*:*:*:*:*
cpe:2.3:a:libssh:libssh:0.11.1:*:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.0017
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 6.5
ubuntu
6 месяцев назад

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads to failed memory allocation and causes the server process to crash, resulting in a denial of service.

CVSS3: 4.3
redhat
7 месяцев назад

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads to failed memory allocation and causes the server process to crash, resulting in a denial of service.

CVSS3: 6.5
debian
6 месяцев назад

A flaw was found in the SFTP server message decoding logic of libssh. ...

CVSS3: 4.3
github
6 месяцев назад

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads to failed memory allocation and causes the server process to crash, resulting in a denial of service.

CVSS3: 4.3
fstec
9 месяцев назад

Уязвимость функции sftp_decode_channel_data_to_packet() библиотеки libssh, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 39%
0.0017
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-190