Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40622
HistoryMay 21, 2023 - 4:19 p.m.

Denial Of Services (DoS)

2023-05-2116:19:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
24
vulnerability
null pointer dereference
rekeying
application crash
client
kexinit message
algorithm guessing

EPSS

0.001

Percentile

46.2%

libssh.so is vulnerable to Denial Of Services (DoS). The vulnerability exists due to a null pointer dereference during rekeying with algorithm guessing, which allows an attacker to cause an application crash when the client initiates rekeying with the first_kex_packet_follows flag in the KEXINIT message.

References