{"schema_version":"1.9.0","id":"CVE-2023-1667","published":"2023-05-26T00:00:00Z","modified":"2026-08-12T03:51:28.356947519Z","related":["ALSA-2023:3839","ALSA-2023:6643","SUSE-SU-2024:0140-1","SUSE-SU-2024:0525-1","SUSE-SU-2024:0539-1","openSUSE-SU-2024:12914-1"],"details":"A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.","affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/libssh/libssh-mirror","events":[{"introduced":"67c0ce3d219a1565491c30d6e5815a73eaea70a4"},{"last_affected":"da6d026c125712d197479a7930b4efc117bfe7af"},{"introduced":"7f6b3fab4e8d4b97e73d5ca60ddc5a3d0f5880d2"},{"last_affected":"e8322817a9e5aaef0698d779ddd467a209a85d85"}],"database_specific":{"cpe":"cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.9.1"},{"last_affected":"0.9.6"},{"introduced":"0.10.0"},{"last_affected":"0.10.4"}],"source":"CPE_RANGE"}}],"versions":["libssh-0.10.4","libssh-0.10.3","libssh-0.10.2","libssh-0.10.0","libssh-0.9.6","libssh-0.9.5","libssh-0.9.4","libssh-0.9.3","libssh-0.9.2","libssh-0.9.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-1667.json"}}],"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2023-1667"},{"type":"ADVISORY","url":"http://www.libssh.org/security/advisories/CVE-2023-1667.txt"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1667.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27PD44ALQTZXX7K6JAM3BXBUHYA6DFFN/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1667"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202312-05"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2182199"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00029.html"}],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1667.json","unresolved_ranges":[{"extracted_events":[{"introduced":"libssh-2"},{"last_affected":"libssh-2"}],"source":"AFFECTED_FIELD"}]}}