CVE-2015-1782

medium
Published 2015-03-13 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-1782

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.libssh2.org/adv_20150311.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.4.3-4.1
debian debianbullseyefixed1.4.3-4.1
debian debianforkyfixed1.4.3-4.1
debian debiansidfixed1.4.3-4.1
debian debiantrixiefixed1.4.3-4.1
fedora fedora20affected
fedora fedora21affected
fedora fedora22affected
debian debian7.0affected

Application impact

VendorProductVersionsFixed
libssh2libssh2{"endIncluding":"1.4.3"}

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.