CVE-2013-0176: Libssh
Medium severity, CVSS 4.3. EPSS: 3% chance of exploitation in the next 30 days.
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.
Affected products
- Libssh Libssh: up to and including 0.5.3; version 0.4.7 only; version 0.4.8 only; version 0.5.0 only; version 0.5.1 only; version 0.5.2 only
Published 2013-02-05. Last modified 2026-06-16.