5.9

CVE-2020-16135

Exploit
libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libssh ≫ Libssh Version 0.9.4
Debian ≫ Debian Linux Version 9.0
Fedoraproject ≫ Fedora Version 32
Fedoraproject ≫ Fedora Version 33
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.11% 0.895
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://bugs.libssh.org/T232
Vendor Advisory
Issue Tracking
https://bugs.libssh.org/rLIBSSHe631ebb3e2247dd25e9678e6827c20dc73b73238
Vendor Advisory
Exploit
Issue Tracking
https://gitlab.com/libssh/libssh-mirror/-/merge_requests/120
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/07/msg00034.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCIKQRKXAAB4HMWM62EPZJ4DVBHIIEG6/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JNW5GBC6JFN76VEWQXMLT5F7VCZ5AJ2E/
https://security.gentoo.org/glsa/202011-05
Third Party Advisory
https://usn.ubuntu.com/4447-1/
Third Party Advisory