net-ssh is vulnerable to Denial of Service (DoS)
58
Medium Risk
The transport packet reader uses the 4-byte wire packet length directly to size the receive buffer without capping it against the RFC 4253 35000-byte limit. Before authentication completes, a malicious server can declare an arbitrarily large packet length and stream data, so the client allocates memory without a bound. The fix rejects any declared packet length above the RFC 4253 maximum.
You are affected if you are using a version that falls within the vulnerable range and you connect to an SSH server that is malicious or compromised.
net-ssh is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 7.3.4.
Upgrade the net-ssh library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.