5.3
CVSSv3

CVE-2023-6918

Published: 19/12/2023 Updated: 10/01/2024
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection.

Vulnerable Product Search on Vulmon Subscribe to Product

libssh libssh

redhat enterprise linux 8.0

redhat enterprise linux 9.0

fedoraproject fedora 38

fedoraproject fedora 39

Vendor Advisories

Debian Bug report logs - #1059059 libssh: CVE-2023-6918 Package: src:libssh; Maintainer for src:libssh is Laurent Bigonville <bigon@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 19 Dec 2023 21:33:01 UTC Severity: important Tags: security, upstream Found in version libssh/0105-3 ...