Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1730

Опубликовано: 09 апр. 2020
Источник: redhat
CVSS3: 5.3

Описание

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.

A flaw was found in the way libssh handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.

Меры по смягчению последствий

Disable AES-CTR ciphers (and DES in libssh 0.8). If you implement a server using libssh we advise to use a prefork model so each session runs in an own process. If you have implemented your server this way this is not really an issue. The client will kill its own connection.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libssh2Not affected
Red Hat Enterprise Linux 7libsshNot affected
Red Hat Enterprise Linux 7libssh2Not affected
Red Hat Enterprise Linux 8libssh2Not affected
Red Hat Enterprise Linux 8libsshFixedRHSA-2020:454504.11.2020
Red Hat Enterprise Linux 8libsshFixedRHSA-2020:454504.11.2020
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8redhat-virtualization-hostFixedRHSA-2020:521824.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1801998libssh: denial of service when handling AES-CTR (or DES) ciphers

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 6 лет назад

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.

CVSS3: 5.3
nvd
почти 6 лет назад

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.

CVSS3: 5.3
debian
почти 6 лет назад

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in t ...

suse-cvrf
почти 6 лет назад

Security update for libssh

suse-cvrf
почти 6 лет назад

Security update for libssh

5.3 Medium

CVSS3