Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted SSH packet.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libssh‘ssh_packet_kexdh_init()’拒绝服务漏洞
Vulnerability Description
libssh是一个用于访问SSH服务的C语言开发包,它能够执行远程命令、文件传输,同时为远程的程序提供安全的传输通道。 libssh 0.6.5之前版本的package_cb.c文件中的SSH_MSG_NEWKEYS和SSH_MSG_KEXDH_REPLY数据包处理器中存在安全漏洞,该漏洞源于程序没有正确验证状态。远程攻击者可通过发送特制的SSH数据包利用该漏洞造成拒绝服务(空指针逆向引用和崩溃)。
CVSS Information
N/A
Vulnerability Type
N/A