CVE-2015-1782: Debian Linux

Medium severity, CVSS 6.8. EPSS: 3.5% chance of exploitation in the next 30 days.

The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Fedoraproject Fedora: version 20 only; version 21 only; version 22 only
  • LIBSSH2 LIBSSH2: up to and including 1.4.3

Published 2015-03-13. Last modified 2026-06-17.