5

CVE-2014-8132

Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.

Data is provided by the National Vulnerability Database (NVD)
LibsshLibssh Version0.5.0
LibsshLibssh Version0.5.2
LibsshLibssh Version0.5.3
LibsshLibssh Version0.5.4
LibsshLibssh Version0.5.5
LibsshLibssh Version0.6.0
LibsshLibssh Version0.6.1
LibsshLibssh Version0.6.2
LibsshLibssh Version0.6.3
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
OpensuseOpensuse Version12.3
OpensuseOpensuse Version13.1
OpensuseOpensuse Version13.2
FedoraprojectFedora Version19
FedoraprojectFedora Version20
FedoraprojectFedora Version21
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version14.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.29% 0.868
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P