MGASA-2015-0209

    Dashboard / Vulnerabilities / MGASA-2015-0209

    MGASA-2015-0209

    Published: 11 May 2015Last Modified: 16 Apr 2026
    Upstream:

    Summary: Updated libssh packages fix CVE-2015-3146

    Details: Updated libssh packages fix security vulnerability: libssh versions 0.5.1 and above, but before 0.6.5, have a logical error in the handling of a SSH_MSG_NEWKEYS and SSH_MSG_KEXDH_REPLY package. A detected error did not set the session into the error state correctly and further processed the packet which leads to a null pointer dereference. This is the packet after the initial key exchange and doesn't require authentication. This could be used for a Denial of Service (DoS) attack (CVE-2015-3146).

    Affected packages

    Package

    Name: libssh

    Purl: pkg:rpm/mageia/libssh?arch=source&distro=mageia-4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.5.5-2.3.mga4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High