[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3487-1 libssh2 -- libssh2

ID: oval:org.secpod.oval:def:602380Date: (C)2016-03-02   (M)2023-07-28
Class: PATCHFamily: unix




Andreas Schneider reported that libssh2, a SSH2 client-side library, passes the number of bytes to a function that expects number of bits during the SSHv2 handshake when libssh2 is to get a suitable value for "group order" in the Diffie-Hellman negotiation. This weakens significantly the handshake security, potentially allowing an eavesdropper with enough resources to decrypt or intercept SSH sessions.

Platform:
Debian 8.x
Debian 7.x
Product:
libssh2-1
Reference:
DSA-3487-1
CVE-2016-0787
CVE    1
CVE-2016-0787
CPE    3
cpe:/a:libssh:libssh2-1
cpe:/o:debian:debian_linux:7.x
cpe:/o:debian:debian_linux:8.x

© SecPod Technologies