VDB
CVE-2012-6063
CVE-2012-6063
PUBLISHED
CVSS 7.5 HIGH
Double free vulnerability in the sftp_mkdir function in sftp.c in libssh before 0.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors, a different vector than CVE-2012-4559.
EPSS 2.14% · 84.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
2.14%
84.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| libssh | libssh | 0.5.1, 0.4.8, 0.5.0 |
| n/a | n/a | * |
Timeline
- Nov 30, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- https://bugzilla.redhat.com/show_bug.cgi?id=871612 url
- DSA-2577 vendor-advisory
- http://www.libssh.org/2012/11/20/libssh-0-5-3-security-release/ url
- http://git.libssh.org/projects/libssh.git/commit/?h=v0-5&id=4d8420f3282ed07fc99fc5e930c17df27ef1e9b2 url
- https://nvd.nist.gov/vuln/detail/CVE-2012-6063 advisory
- http://www.libssh.org/2012/11/20/libssh-0-5-3-security-release url