Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 460620 - <net-libs/libssh-0.5.4: DoS vulnerability (CVE-2013-0176)
Summary: <net-libs/libssh-0.5.4: DoS vulnerability (CVE-2013-0176)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-03-06 23:43 UTC by GLSAMaker/CVETool Bot
Modified: 2013-03-24 20:23 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2013-03-06 23:43:28 UTC
CVE-2013-0176 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0176):
  The publickey_from_privatekey function in libssh before 0.5.4, when no
  algorithm is matched during negotiations, allows remote attackers to cause a
  denial of service (NULL pointer dereference and crash) via a "Client:
  Diffie-Hellman Key Exchange Init" packet.


Maintainers, is =net-libs/libssh-0.5.4 ready for stabilization?
Comment 1 Tim Harder gentoo-dev 2013-03-07 04:58:12 UTC
Arches go ahead.
Comment 2 Agostino Sarubbo gentoo-dev 2013-03-07 18:02:15 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2013-03-07 18:04:53 UTC
x86 stable
Comment 4 Agostino Sarubbo gentoo-dev 2013-03-09 11:03:00 UTC
ppc64 stable
Comment 5 Agostino Sarubbo gentoo-dev 2013-03-09 11:25:54 UTC
ppc stable
Comment 6 Sean Amoss (RETIRED) gentoo-dev Security 2013-03-11 22:33:25 UTC
GLSA vote: no
Comment 7 Michael Palimaka (kensington) gentoo-dev 2013-03-14 15:38:16 UTC
Vulnerable version removed.
Comment 8 Tobias Heinlein (RETIRED) gentoo-dev 2013-03-24 20:23:58 UTC
NO too, closing.