Lucene search

K
ubuntuUbuntuUSN-2145-1
HistoryMar 12, 2014 - 12:00 a.m.

libssh vulnerability

2014-03-1200:00:00
ubuntu.com
44

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

AI Score

5.8

Confidence

Low

EPSS

0

Percentile

5.1%

Releases

  • Ubuntu 13.10
  • Ubuntu 12.10
  • Ubuntu 12.04

Packages

  • libssh - A tiny C SSH library

Details

Aris Adamantiadis discovered that libssh allowed the OpenSSL PRNG state to
be reused when implementing forking servers. This could allow an attacker
to possibly obtain information about the state of the PRNG and perform
cryptographic attacks.

OSVersionArchitecturePackageVersionFilename
Ubuntu13.10noarchlibssh-4<Β 0.5.4-1ubuntu0.1UNKNOWN
Ubuntu13.10noarchlibssh-dbg<Β 0.5.4-1ubuntu0.1UNKNOWN
Ubuntu13.10noarchlibssh-dev<Β 0.5.4-1ubuntu0.1UNKNOWN
Ubuntu12.10noarchlibssh-4<Β 0.5.2-1ubuntu0.12.10.3UNKNOWN
Ubuntu12.10noarchlibssh-dbg<Β 0.5.2-1ubuntu0.12.10.3UNKNOWN
Ubuntu12.10noarchlibssh-dev<Β 0.5.2-1ubuntu0.12.10.3UNKNOWN
Ubuntu12.04noarchlibssh-4<Β 0.5.2-1ubuntu0.12.04.3UNKNOWN
Ubuntu12.04noarchlibssh-dbg<Β 0.5.2-1ubuntu0.12.04.3UNKNOWN
Ubuntu12.04noarchlibssh-dev<Β 0.5.2-1ubuntu0.12.04.3UNKNOWN

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

AI Score

5.8

Confidence

Low

EPSS

0

Percentile

5.1%