{"id":"CVE-2016-0739","details":"libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a \"bits/bytes confusion bug.\"","modified":"2026-04-16T06:16:20.669060264Z","published":"2016-04-13T17:59:08.413Z","related":["SUSE-SU-2016:0622-1","SUSE-SU-2016:0625-1"],"references":[{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178058.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2016-03/msg00111.html"},{"type":"WEB","url":"https://puppet.com/security/cve/CVE-2016-0739"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178822.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2016-0566.html"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2912-1"},{"type":"ADVISORY","url":"https://www.libssh.org/2016/02/23/libssh-0-7-3-security-and-bugfix-release/"},{"type":"ADVISORY","url":"https://www.libssh.org/security/advisories/CVE-2016-0739.txt"},{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3488"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201606-12"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/libssh/libssh-mirror","events":[{"introduced":"0"},{"last_affected":"186e7b5ca47450d10b7ed8996de2b640342599bf"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"0.7.2"}]}}],"versions":["libssh-0.7.0","libssh-0.7.1","libssh-0.7.2","release-0-3-0"],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"7.0"}]},{"events":[{"introduced":"0"},{"last_affected":"12.04"}]},{"events":[{"introduced":"0"},{"last_affected":"14.04"}]},{"events":[{"introduced":"0"},{"last_affected":"15.10"}]},{"events":[{"introduced":"0"},{"last_affected":"22"}]},{"events":[{"introduced":"0"},{"last_affected":"23"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0"}]},{"events":[{"introduced":"0"},{"last_affected":"8.0"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0739.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}