Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1730

Опубликовано: 09 апр. 2020
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.

A flaw was found in the way libssh handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.

Меры по смягчению последствий

Disable AES-CTR ciphers (and DES in libssh 0.8). If you implement a server using libssh we advise to use a prefork model so each session runs in an own process. If you have implemented your server this way this is not really an issue. The client will kill its own connection.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libssh2Not affected
Red Hat Enterprise Linux 7libsshNot affected
Red Hat Enterprise Linux 7libssh2Not affected
Red Hat Enterprise Linux 8libssh2Not affected
Red Hat Enterprise Linux 8libsshFixedRHSA-2020:454504.11.2020
Red Hat Enterprise Linux 8libsshFixedRHSA-2020:454504.11.2020
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8redhat-virtualization-hostFixedRHSA-2020:521824.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1801998libssh: denial of service when handling AES-CTR (or DES) ciphers

EPSS

Процентиль: 23%
0.00076
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 5 лет назад

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.

CVSS3: 5.3
nvd
больше 5 лет назад

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.

CVSS3: 5.3
debian
больше 5 лет назад

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in t ...

suse-cvrf
больше 5 лет назад

Security update for libssh

suse-cvrf
больше 5 лет назад

Security update for libssh

EPSS

Процентиль: 23%
0.00076
Низкий

5.3 Medium

CVSS3