5

CVE-2012-4561

The (1) publickey_make_dss, (2) publickey_make_rsa, (3) signature_from_string, (4) ssh_do_sign, and (5) ssh_sign_session_id functions in keys.c in libssh before 0.5.3 free "an invalid pointer on an error path," which might allow remote attackers to cause a denial of service (crash) via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
LibsshLibssh Version <= 0.5.2
LibsshLibssh Version0.4.7
LibsshLibssh Version0.4.8
LibsshLibssh Version0.5.0
LibsshLibssh Version0.5.0 Updaterc1
LibsshLibssh Version0.5.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.71% 0.868
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P