CVE-2013-0176: Libssh

Medium severity, CVSS 4.3. EPSS: 3% chance of exploitation in the next 30 days.

The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.

Affected products

  • Libssh Libssh: up to and including 0.5.3; version 0.4.7 only; version 0.4.8 only; version 0.5.0 only; version 0.5.1 only; version 0.5.2 only

Published 2013-02-05. Last modified 2026-06-16.