Vulnerability Bulletins |
DSA-3182 libssh2 - security update |
|
| Affected software | Debian |
|
Mariusz Ziulek reported that libssh2, a SSH2 client-side library, wasreading and using the SSH_MSG_KEXINIT packet without doing sufficientrange checks when negotiating a new SSH session with a remote server. Amalicious attacker could man in the middle a real server and cause aclient using the libssh2 library to crash (denial of service) orotherwise read and use unintended memory areas in this process. More info: https://www.debian.org/security/2015/dsa-3182 |
|






