Vulnerability Bulletins |
DSA-3488 libssh - security update |
|
| Affected software | Debian |
|
Aris Adamantiadis discovered that libssh, a tiny C SSH library,incorrectly generated a short ephemeral secret for thediffie-hellman-group1 and diffie-hellman-group14 key exchange methods.The resulting secret is 128 bits long, instead of the recommended sizesof 1024 and 2048 bits respectively. This flaw could allow aneavesdropper with enough resources to decrypt or intercept SSH sessions. More info: https://www.debian.org/security/2016/dsa-3488 |
|






