VulnerabilityModified
CVE-2020-1730
The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection.
MEDIUM 5.3EPSS 3.14%
Does this matter?
Lower severity and a low EPSS score (3.14%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 3.14% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- libssh/libssh · netapp/cloud backup · canonical/ubuntu linux · fedoraproject/fedora · redhat/enterprise linux · oracle/mysql workbench
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1730Issue Tracking, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2A7BIFKUYIYKTY7FX4BEWVC2OHS5DPOU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VLSWHBQ3EPKGTGLQNH554Z746BJ3C554/
- https://security.netapp.com/advisory/ntap-20200424-0001/Third Party Advisory
- https://usn.ubuntu.com/4327-1/Third Party Advisory
- https://www.libssh.org/security/advisories/CVE-2020-1730.txtVendor Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1730Issue Tracking, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2A7BIFKUYIYKTY7FX4BEWVC2OHS5DPOU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VLSWHBQ3EPKGTGLQNH554Z746BJ3C554/
- https://security.netapp.com/advisory/ntap-20200424-0001/Third Party Advisory
- https://usn.ubuntu.com/4327-1/Third Party Advisory
- https://www.libssh.org/security/advisories/CVE-2020-1730.txtVendor Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.