• CVE-2025-4878

发布时间: 2025年9月5日

修改时间: 2025年9月12日

概要

A vulnerability, which was classified as problematic, has been found in libssh up to 0.11.1.Using CWE to declare the problem leads to CWE-824. The product accesses or uses a pointer that has not been initialized.Impacted is confidentiality, integrity, and availability.Upgrading to version 0.11.2 eliminates this vulnerability.

CVSS v3 指标

NVD openEuler
Confidentiality Low
Attack Vector Local
CVSS评分 N/A 3.6
Attack Complexity High
Privileges Required Low
Scope Unchanged
Integrity Low
User Interaction None
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2850 libssh security update 2025年9月25日
KylinSec-SA-2025-2863 libssh security update 2025年9月12日

影响产品

产品 状态
KY3.4-5A libssh Fixed
V6 libssh Fixed
KY3.5.3 libssh Fixed
KY3.5.2 libssh Fixed