Lucene search

K
ubuntuUbuntuUSN-2478-1
HistoryJan 19, 2015 - 12:00 a.m.

libssh vulnerability

2015-01-1900:00:00
ubuntu.com
48

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.7

Confidence

High

EPSS

0.126

Percentile

95.5%

Releases

  • Ubuntu 14.10
  • Ubuntu 14.04 ESM
  • Ubuntu 12.04

Packages

  • libssh - A tiny C SSH library

Details

It was discovered that libssh incorrectly handled certain kexinit packets.
A remote attacker could possibly use this issue to cause libssh to crash,
resulting in a denial of service.

OSVersionArchitecturePackageVersionFilename
Ubuntu14.10noarchlibssh-4< 0.6.3-2ubuntu1.1UNKNOWN
Ubuntu14.10noarchlibssh-dbg< 0.6.3-2ubuntu1.1UNKNOWN
Ubuntu14.10noarchlibssh-dev< 0.6.3-2ubuntu1.1UNKNOWN
Ubuntu14.04noarchlibssh-4< 0.6.1-0ubuntu3.1UNKNOWN
Ubuntu14.04noarchlibssh-dbg< 0.6.1-0ubuntu3.1UNKNOWN
Ubuntu14.04noarchlibssh-dev< 0.6.1-0ubuntu3.1UNKNOWN
Ubuntu12.04noarchlibssh-4< 0.5.2-1ubuntu0.12.04.4UNKNOWN
Ubuntu12.04noarchlibssh-dbg< 0.5.2-1ubuntu0.12.04.4UNKNOWN
Ubuntu12.04noarchlibssh-dev< 0.5.2-1ubuntu0.12.04.4UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.7

Confidence

High

EPSS

0.126

Percentile

95.5%