Libssh type Obfuscation Vulnerability (CVE-2016-0739)
Libssh type Obfuscation Vulnerability (CVE-2016-0739)
Release date:
Updated on:
Affected Systems:
Libssh
Description:
CVE (CAN) ID: CVE-2016-0739
Libssh is a C language development kit used to access the SSH service. It can execute remote commands and file transmission, and provide a secure transmission channel for remote programs.
A type Obfuscation Vulnerability exists in the temporary password for libssh generation of diffie-hellman-group1/diffie-hellman-group14 key exchange methods that can cause SSHv2 Diffie-Hellman handshakes to use insecure random parameters.
<* Source: Aris Adamantiadis
*>
Suggestion:
Vendor patch:
Libssh
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Www.libssh.org
This article permanently updates the link address: