{"id":"MGASA-2015-0014","summary":"Updated libssh packages fix CVE-2014-8132","details":"Updated libssh packages fix security vulnerability:\n\nDouble free vulnerability in the ssh_packet_kexinit function in kex.c in\nlibssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial\nof service via a crafted kexinit packet (CVE-2014-8132).\n","modified":"2026-04-16T06:25:40.678238283Z","published":"2015-01-08T12:36:22Z","upstream":["CVE-2014-8132"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0014.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14957"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2015-January/147464.html"}],"affected":[{"package":{"name":"libssh","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/libssh?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.5-2.2.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0014.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}