The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted SSH packet.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2016-04-13T17:00:00

Updated: 2024-08-06T05:39:32.028Z

Reserved: 2015-04-10T00:00:00

Link: CVE-2015-3146

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2016-04-13T17:59:03.100

Modified: 2016-04-20T15:07:16.900

Link: CVE-2015-3146

cve-icon Redhat

Severity : Moderate

Publid Date: 2015-04-30T00:00:00Z

Links: CVE-2015-3146 - Bugzilla