suse · CVE-2016-0787

Quick triage

Priority: medium 公開: 2021-05-30 13:37:17 UTC Updated: 2026-04-18 18:04:08 UTC

参照: Official suse advisory, NVD, CVE.org · CVE 詳細

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-0787 severity moderate: SUSE including 276 source package names (0.9.1:libssh2-1-1.4.3-16.1, 1.0.0:libssh2-1-1.4.3-16.1, …), 332 product×package rows across 68 product lines (Container caasp/v4/default-http-backend, Container caasp/v4/dnsmasq-nanny, … (68 product lines)): Known Affected 231, Fixed 101.

Description:

The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."

cvelogic Threat Intelligence