Denial of Service Vulnerability in libssh2's kex_agree_methods Function

Denial of Service Vulnerability in libssh2's kex_agree_methods Function

CVE-2015-1782 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.

Learn more about our Cis Benchmark Audit For Server Software.