Back

HIGH

openssh: uninitialized variable use in J-PAKE implementation

Published Jan 29, 2014

Description

The hash_buffer function in schnorr.c in OpenSSH through 6.4, when Makefile.inc is modified to enable the J-PAKE protocol, does not initialize certain data structures, which might allow remote attackers to cause a denial of service (memory corruption) or have unspecified other impact via vectors that trigger an error condition.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of openssh as shipped with Red Hat Enterprise Linux 4, 5, or 6, as the code for J-PAKE support is not compiled into the Red Hat shipped binaries.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 29, 2014
Updated May 28, 2026
Reserved Jan 29, 2014
CISA Vulnrichment
Updated May 28, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Jan 29, 2013