[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3488-1 libssh -- libssh

ID: oval:org.secpod.oval:def:602384Date: (C)2016-03-02   (M)2022-09-22
Class: PATCHFamily: unix




Aris Adamantiadis discovered that libssh, a tiny C SSH library, incorrectly generated a short ephemeral secret for the diffie-hellman-group1 and diffie-hellman-group14 key exchange methods. The resulting secret is 128 bits long, instead of the recommended sizes of 1024 and 2048 bits respectively. This flaw could allow an eavesdropper with enough resources to decrypt or intercept SSH sessions.

Platform:
Debian 8.x
Debian 7.x
Product:
libssh-dev
Reference:
DSA-3488-1
CVE-2016-0739
CVE-2014-8132
CVE-2015-3146
CVE    3
CVE-2016-0739
CVE-2014-8132
CVE-2015-3146
CPE    3
cpe:/a:libssh:libssh-dev
cpe:/o:debian:debian_linux:7.x
cpe:/o:debian:debian_linux:8.x

© SecPod Technologies