CVE-2015-1782
Publication date 13 March 2015
Last updated 24 July 2024
Ubuntu priority
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.
From the Ubuntu Security Team
It was discovered that libssh2 mishandled certain input. If libssh2 were used to connect to a malicious or compromised SSH server, the server could cause the client to crash.
Status
Package | Ubuntu Release | Status |
---|---|---|
libssh2 | ||
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 1.4.3-2ubuntu0.2
|
|