FreeBSD : libssh -- NULL pointer dereference (0b040e24-f751-11e4-b24d-5453ed2e2b49)
Medium Nessus Plugin ID 83328
SynopsisThe remote FreeBSD host is missing a security-related update.
DescriptionAndreas Schneider reports :
libssh versions 0.5.1 and above have a logical error in the handling of a SSH_MSG_NEWKEYS and SSH_MSG_KEXDH_REPLY package. A detected error did not set the session into the error state correctly and further processed the packet which leads to a NULL pointer dereference. This is the packet after the initial key exchange and doesn't require authentication.
This could be used for a Denial of Service (DoS) attack.
SolutionUpdate the affected package.