CyberRota Analysis
AI-GeneratedA vulnerability in Exchange allows for an out-of-bounds heap read due to improper length validation of a client-supplied Curve25519 public key during server-side GSSAPI key exchange. This flaw could enable a remote, unauthenticated attacker to disclose small amounts of server memory, potentially exposing sensitive information. Organizations using affected versions of Exchange should prioritize remediation to mitigate the risk of data leakage.
Original NVD Description
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.
Related CVEs
Other vulnerabilities affecting the same vendor(s)