A flaw was found in libssh versions before 0.8.9 and...
Vulnerability Description
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-1730
Credits & Attribution
No credits recorded in the NVD database.
References
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VLSWHBQ3EPKGTGLQNH554Z746BJ3C554/
- https://usn.ubuntu.com/4327-1/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2A7BIFKUYIYKTY7FX4BEWVC2OHS5DPOU/
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.libssh.org/security/advisories/CVE-2020-1730.txt
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1730
- https://security.netapp.com/advisory/ntap-20200424-0001/
More from Red Hat
View All →Affected Vendor
Red Hat
View all reports →