Lucene search

K
cvelistRedhatCVELIST:CVE-2016-0787
HistoryApr 13, 2016 - 5:00 p.m.

CVE-2016-0787

2016-04-1317:00:00
redhat
www.cve.org
2

5.8 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.6%

The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a “bits/bytes confusion bug.”