5.3

CVE-2020-1730

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libssh ≫ Libssh Version >= 0.8.0 < 0.8.9
Libssh ≫ Libssh Version >= 0.9.0 < 0.9.4
Netapp ≫ Cloud Backup Version -
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Redhat ≫ Enterprise Linux Version 8.0
Oracle ≫ Mysql Workbench Version <= 8.0.21
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.07% 0.859
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://www.oracle.com/security-alerts/cpuoct2020.html
Patch
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1730
Third Party Advisory
Issue Tracking
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2A7BIFKUYIYKTY7FX4BEWVC2OHS5DPOU/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VLSWHBQ3EPKGTGLQNH554Z746BJ3C554/
https://security.netapp.com/advisory/ntap-20200424-0001/
Third Party Advisory
https://usn.ubuntu.com/4327-1/
Third Party Advisory
https://www.libssh.org/security/advisories/CVE-2020-1730.txt
Vendor Advisory