CVE-2014-0017: Libssh
Low severity, CVSS 1.9. EPSS: 0.4% chance of exploitation in the next 30 days.
The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtain sensitive information by leveraging a pid collision.
Affected products
- Libssh Libssh: up to and including 0.6.2; version 0.4.7 only; version 0.4.8 only; version 0.5.0 only; version 0.5.1 only; version 0.5.2 only; …
Published 2014-03-14. Last modified 2026-06-17.