CVE-2020-16135
Moderate
CVE-2020-16135
libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
Exploit probability
4.1%
Published
July 29, 2020
Required by
Not available
Last source change
July 8, 2026
02 / AFFECTED SOFTWARE
Affected packages
2 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2020-16135
View original source
libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
05 / REFERENCES
Further evidence
- https://bugs.libssh.org/T232
- https://bugs.libssh.org/rLIBSSHe631ebb3e2247dd25e9678e6827c20dc73b73238
- https://gitlab.com/libssh/libssh-mirror/-/merge_requests/120
- https://lists.debian.org/debian-lts-announce/2020/07/msg00034.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCIKQRKXAAB4HMWM62EPZJ4DVBHIIEG6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JNW5GBC6JFN76VEWQXMLT5F7VCZ5AJ2E/
- https://security.gentoo.org/glsa/202011-05
- https://usn.ubuntu.com/4447-1/
- https://www.oracle.com/security-alerts/cpuapr2022.html