Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-4878

Опубликовано: 24 июн. 2025
Источник: redhat
CVSS3: 3.6
EPSS Низкий

Описание

A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.

Отчет

Red Hat Product Security has rated this vulnerability as having Low severity as the affected privatekey_from_file() function is deprecated and should not be used.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsshFix deferred
Red Hat Enterprise Linux 6libssh2Out of support scope
Red Hat Enterprise Linux 7libssh2Out of support scope
Red Hat Enterprise Linux 8libsshFix deferred
Red Hat Enterprise Linux 9libsshFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2376184libssh: Use of uninitialized variable in privatekey_from_file()

EPSS

Процентиль: 1%
0.00013
Низкий

3.6 Low

CVSS3

Связанные уязвимости

CVSS3: 3.6
ubuntu
26 дней назад

A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.

CVSS3: 3.6
nvd
26 дней назад

A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.

CVSS3: 3.6
debian
26 дней назад

A vulnerability was found in libssh, where an uninitialized variable e ...

CVSS3: 3.6
github
26 дней назад

A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the filename doesn't exist and may lead to possible signing failures or heap corruption.

CVSS3: 3.6
fstec
4 месяца назад

Уязвимость функции privatekey_from_file() библиотеки libssh, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании

EPSS

Процентиль: 1%
0.00013
Низкий

3.6 Low

CVSS3