Vulnerabilities > CVE-2020-16135 - NULL Pointer Dereference vulnerability in multiple products
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 | |
OS | 1 | |
OS | 2 | |
OS | 3 |
Common Weakness Enumeration (CWE)
References
- https://bugs.libssh.org/rLIBSSHe631ebb3e2247dd25e9678e6827c20dc73b73238
- https://bugs.libssh.org/T232
- https://gitlab.com/libssh/libssh-mirror/-/merge_requests/120
- https://lists.debian.org/debian-lts-announce/2020/07/msg00034.html
- https://usn.ubuntu.com/4447-1/
- https://security.gentoo.org/glsa/202011-05
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JNW5GBC6JFN76VEWQXMLT5F7VCZ5AJ2E/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCIKQRKXAAB4HMWM62EPZJ4DVBHIIEG6/