CVE-2014-0017: Libssh

Low severity, CVSS 1.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtain sensitive information by leveraging a pid collision.

Affected products

  • Libssh Libssh: up to and including 0.6.2; version 0.4.7 only; version 0.4.8 only; version 0.5.0 only; version 0.5.1 only; version 0.5.2 only; …

Published 2014-03-14. Last modified 2026-06-17.