CVE-2015-1782 PUBLISHED

The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.

EPSS 4.68% · 89.3th percentile

Risk Scores

EPSS Score
4.68%
89.3th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlibssh20, 1.4.3-1, 1.4.3-2

Timeline

References

Open in Interactive Console →