Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
libssh 安全漏洞
Vulnerability Description
libssh是一个用于访问SSH服务的C语言开发包,它能够执行远程命令、文件传输,同时为远程的程序提供安全的传输通道。 libssh 0.7.3之前版本中存在安全漏洞,该漏洞源于程序没有正确将diffie-hellman-group1和diffie-hellman-group14密钥交换算法的临时密钥缩短为128位。攻击者可利用该漏洞实施中间人攻击,解密或拦截SSH会话。
CVSS Information
N/A
Vulnerability Type
N/A