CVE-2020-1730
Summary
| CVE | CVE-2020-1730 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-13 19:15:00 UTC |
| Updated | 2023-11-07 03:19:00 UTC |
| Description | A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 31 Update: libssh-0.9.4-2.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 31 Update: libssh-0.9.4-2.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE-2020-1730 Libssh Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| Oracle Critical Patch Update Advisory - October 2020 |
MISC |
www.oracle.com |
|
| www.libssh.org/security/advisories/CVE-2020-1730.txt |
MISC |
www.libssh.org |
Vendor Advisory |
| 1801998 – (CVE-2020-1730) CVE-2020-1730 libssh: denial of service when handling AES-CTR (or DES) ciphers |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 32 Update: libssh-0.9.4-2.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| USN-4327-1: libssh vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] Fedora 32 Update: libssh-0.9.4-2.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377559 Alibaba Cloud Linux Security Update for libssh (ALINUX3-SA-2022:0067)
- 501063 Alpine Linux Security Update for libssh
- 755806 SUSE Enterprise Linux Security Update for libssh (SUSE-SU-2024:0539-1)
- 770068 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2021:0436)
- 940406 AlmaLinux Security Update for libssh (ALSA-2020:4545)
- 960879 Rocky Linux Security Update for libssh (RLSA-2020:4545)