VDB

DEBIAN-CVE-2023-6918

DEBIAN-CVE-2023-6918 PUBLISHED CVSS 5.300000190734863 MEDIUM

A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection.

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersions
Debian:13libssh0, 0, 0
Debian:12libssh0.10.5-2, 0.10.5-3, *
Debian:11libssh0.9.6-2, 0.9.7-0+deb11u1, 0.9.6-1
Debian:14libssh0, 0, 0

Timeline

  • Dec 19, 2023 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›