{"schema_version":"1.8.0","id":"CVE-2016-0787","published":"2016-04-13T17:59:10.930Z","modified":"2026-08-07T11:31:07.086876178Z","related":["SUSE-SU-2016:0718-1","SUSE-SU-2016:0723-1","SUSE-SU-2017:2699-1","SUSE-SU-2017:2700-1","openSUSE-SU-2024:10190-1"],"details":"The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a \"bits/bytes confusion bug.\"","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libssh2/libssh2","events":[{"introduced":"0"},{"last_affected":"cbd5f72339dae6bfc587f4486f4349dd1d61f9b7"}],"database_specific":{"cpe":"cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.6.0"}],"source":"CPE_RANGE"}}],"versions":["libssh2-1.6.0","libssh2-1.5.0","libssh2-1.4.3","libssh2-1.4.2","libssh2-1.4.1","libssh2-1.4.0","libssh2-1.3.0","libssh2-1.2.9","libssh2-1.2.8","libssh2-1.2.7","libssh2-1.2.6","libssh2-1.2.5","libssh2-1.2.4","libssh2-1.2.3","libssh2-1.2.1","libssh2-1.2","RELEASE.1.1","RELEASE.1.0","RELEASE.0.18","RELEASE.0.17","RELEASE.0.16","RELEASE.0.15","beforenb2-0.14","beforenb-0.14","RELEASE.0.14","RELEASE.0.13","RELEASE.0.12","RELEASE.0.11","RELEASE.0.10","RELEASE.0.8","RELEASE.0.7","RELEASE.0.6","RELEASE.0.5","RELEASE.0.3","RELEASE.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0787.json"}}],"references":[{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177980.html"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178573.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2016-03/msg00008.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/82514"},{"type":"WEB","url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10156"},{"type":"WEB","url":"https://puppet.com/security/cve/CVE-2016-0787"},{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3487"},{"type":"ADVISORY","url":"https://bto.bluecoat.com/security-advisory/sa120"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201606-12"},{"type":"ADVISORY","url":"https://www.libssh2.org/adv_20160223.html"},{"type":"FIX","url":"https://www.libssh2.org/CVE-2016-0787.patch"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"},{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"cpes":["cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"22"},{"last_affected":"22"},{"introduced":"23"},{"last_affected":"23"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"},{"cpes":["cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"13.2"},{"last_affected":"13.2"}],"source":"CPE_STRING","vendor_product":"opensuse:opensuse"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}