[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2879-1 libssh -- libssh

ID: oval:org.secpod.oval:def:601228Date: (C)2014-04-04   (M)2022-10-10
Class: PATCHFamily: unix




It was discovered that libssh, a tiny C SSH library, did not reset the state of the PRNG after accepting a connection. A server mode application that forks itself to handle incoming connections could see its children sharing the same PRNG state, resulting in a cryptographic weakness and possibly the recovery of the private key.

Platform:
Debian 7.0
Debian 6.0
Product:
libssh-dev
Reference:
DSA-2879-1
CVE-2014-0017
CVE    1
CVE-2014-0017
CPE    3
cpe:/a:libssh:libssh-dev
cpe:/o:debian:debian_linux:6.0
cpe:/o:debian:debian_linux:7.0

© SecPod Technologies