FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

nothing found there

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
3d7dfd63-823b-11ea-b3a8-240a644dd835Client/server denial of service when handling AES-CTR ciphers

The libssh team reports (originally reported by Yasheng Yang from Google):

A malicious client or server could crash the counterpart implemented with libssh AES-CTR ciphers are used and don't get fully initialized. It will crash when it tries to cleanup the AES-CTR ciphers when closing the connection.


Discovery 2020-01-25
Entry 2020-04-19
libssh
ge 0.8.0 lt 0.8.9

ge 0.9.0 lt 0.9.4

https://www.libssh.org/security/advisories/CVE-2020-1730.txt"
CVE-2020-1730