CVE-2023-1667: Null Pointer Dereference
A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.
Other sources
In libssh before versions 0.10.5 and 0.9.7 a NULL pointer dereference during rekeying with algorithm guessing may lead to remote denial of service from authenticated clients.
— Red Hat
libssh is vulnerable to a denial of service, caused by a NULL pointer dereference during rekeying with algorithm guessing. A remote authenticated attacker could exploit this vulnerability to cause the daemon to crash.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1667?
CVE-2023-1667 is a vulnerability found in libssh that can cause a denial of service.
How severe is CVE-2023-1667?
CVE-2023-1667 has a severity rating of 6.5, which is considered medium.
How does CVE-2023-1667 affect libssh?
CVE-2023-1667 affects libssh during re-keying with algorithm guessing.
How can an authenticated client exploit CVE-2023-1667?
An authenticated client can exploit CVE-2023-1667 to cause a denial of service.
Where can I find more information about CVE-2023-1667?
You can find more information about CVE-2023-1667 at the following references: [https://bugzilla.redhat.com/show_bug.cgi?id=2182199](https://bugzilla.redhat.com/show_bug.cgi?id=2182199), [http://www.libssh.org/security/advisories/CVE-2023-1667.txt](http://www.libssh.org/security/advisories/CVE-2023-1667.txt), [https://access.redhat.com/security/cve/CVE-2023-1667](https://access.redhat.com/security/cve/CVE-2023-1667).