Unrated severityNVD Advisory· Published Feb 5, 2013· Updated Apr 29, 2026
CVE-2013-0176
CVE-2013-0176
Description
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.
Affected products
7cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*range: <=0.5.3
- cpe:2.3:a:libssh:libssh:0.4.7:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.5.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:libssh:libssh:0.5.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.libssh.org/2013/01/22/libssh-0-5-4-security-release/nvdPatchVendor Advisory
- secunia.com/advisories/51982nvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2013-February/098065.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2013-February/098094.htmlnvd
- www.ubuntu.com/usn/USN-1707-1nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/81595nvd
News mentions
0No linked articles in our index yet.