Information disclosure in libssh - CVE-2016-0739
Published: April 13, 2016 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
Affected software
libssh (Alpine package)
libssh
libssh (Red Hat package)
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Server from RHUI
Slackware Linux
How to mitigate CVE-2016-0739
libssh (Alpine package) - addressed in versions 0.6.5-r0, 0.6.5-r1
libssh - addressed in versions 0.5.5-5.el6, 0.6.5-2.el7, 0.7.3-1.fc22, 0.7.3-1.fc23
libssh (Red Hat package) - update to 0.7.1-2.el7
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178058.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178822.html
- http://lists.opensuse.org/opensuse-updates/2016-03/msg00111.html
- http://rhn.redhat.com/errata/RHSA-2016-0566.html
- http://www.debian.org/security/2016/dsa-3488
- http://www.ubuntu.com/usn/USN-2912-1
- https://puppet.com/security/cve/CVE-2016-0739
- https://security.gentoo.org/glsa/201606-12
- https://www.libssh.org/2016/02/23/libssh-0-7-3-security-and-bugfix-release/
- https://www.libssh.org/security/advisories/CVE-2016-0739.txt