libssh: authorization bypass in pki_verify_data_signature
Published May 26, 2023
6.5
MEDIUMCVSS 3.1
EPSS 1.06%
Description
A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the return value `rc,` which is initialized to SSH_ERROR and later rewritten to save the return value of the function call `pki_key_check_hash_compatible.` The value of the variable is not changed between this point and the cryptographic verification. Therefore any error between them calls `goto error` returning SSH_OK.
Affected products
- Vendor n/a Product Libssh Defaultn/a
- Version libssh-2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Libssh | n/a |
|
Configuration 1
Configuration 2
- 37
Configuration 3
- 8.0
- 9.0
No data.
Red Hat Enterprise Linux 8
libssh-0:0.9.6-10.el8_8
Fixed · RHSA-2023:3839
Red Hat Enterprise Linux 8
libssh-0:0.9.6-10.el8_8
Fixed · RHSA-2023:3839
Red Hat Enterprise Linux 8.6 Extended Update Support
libssh-0:0.9.6-4.el8_6
Fixed · RHSA-2024:0538
Red Hat Enterprise Linux 9
libssh-0:0.10.4-11.el9
Fixed · RHSA-2023:6643
Red Hat Enterprise Linux 9
libssh-0:0.10.4-11.el9
Fixed · RHSA-2023:6643
CloudForms Management Engine 5
libssh2
Out of support scope
Red Hat Enterprise Linux 6
libssh2
Out of support scope
Red Hat Enterprise Linux 7
libssh
Out of support scope
Red Hat Enterprise Linux 7
libssh2
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | libssh-0:0.9.6-10.el8_8 | Fixed | RHSA-2023:3839 |
| Red Hat Enterprise Linux 8 | libssh-0:0.9.6-10.el8_8 | Fixed | RHSA-2023:3839 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | libssh-0:0.9.6-4.el8_6 | Fixed | RHSA-2024:0538 |
| Red Hat Enterprise Linux 9 | libssh-0:0.10.4-11.el9 | Fixed | RHSA-2023:6643 |
| Red Hat Enterprise Linux 9 | libssh-0:0.10.4-11.el9 | Fixed | RHSA-2023:6643 |
| CloudForms Management Engine 5 | libssh2 | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | libssh2 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libssh | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libssh2 | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- http://packetstormsecurity.com/files/172861/libssh-0.9.6-0.10.4-pki_verify_data_signature-Authorization-Bypass.html
- http://seclists.org/fulldisclosure/2025/Feb/18
- https://access.redhat.com/security/cve/CVE-2023-2283 Third Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2189736 Issue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-33789 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27PD44ALQTZXX7K6JAM3BXBUHYA6DFFN/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-2283
- https://security.gentoo.org/glsa/202312-05 vendor-advisory
- https://security.netapp.com/advisory/ntap-20240201-0005/
- https://www.cve.org/CVERecord?id=CVE-2023-2283
- https://www.libssh.org/security/advisories/CVE-2023-2283.txt Vendor Advisory
Change history (0)
No recorded changes yet.