CVE-2013-0176
EPSS 1.0%
Description
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.
How to fix CVE-2013-0176
To remediate CVE-2013-0176, upgrade the affected package to a fixed version below.
- Debian/libssh—upgrade to 0.5.4-1 or later
Is CVE-2013-0176 being exploited?
Low — EPSS is 1.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.5.4-1