CVE-2015-1782
libssh2 - security update
EPSS 3.5%
描述
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.
如何修補 CVE-2015-1782
要修補 CVE-2015-1782,請將受影響套件升級到下列已修補版本。
- Debian/libssh2—升級至 1.4.3-4.1 或更新版本
- Debian/libssh2—升級至 1.2.6-1+deb6u1 或更新版本
- Debian/libssh2—升級至 1.4.2-1.1+deb7u1 或更新版本
CVE-2015-1782 正在被利用嗎?
低 — EPSS 為 3.5%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 1.4.3-4.1
- from 0, < 1.2.6-1+deb6u1
- from 0, < 1.4.2-1.1+deb7u1