Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-16905

Опубликовано: 09 окт. 2019
Источник: nvd
CVSS3: 7.8
CVSS2: 4.4
EPSS Низкий

Описание

OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
Версия от 7.7 (включая) до 7.9 (включая)
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
Версия от 8.0 (включая) до 8.1 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:siemens:scalance_x204rna_firmware:*:*:*:*:*:*:*:*
Версия до 3.2.7 (исключая)
cpe:2.3:h:siemens:scalance_x204rna:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

cpe:2.3:o:siemens:scalance_x204rna_ecc_firmware:*:*:*:*:*:*:*:*
Версия до 3.2.7 (исключая)
cpe:2.3:h:siemens:scalance_x204rna_ecc:-:*:*:*:*:*:*:*

EPSS

Процентиль: 32%
0.00123
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 6 лет назад

OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.

CVSS3: 8.8
redhat
около 6 лет назад

OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.

CVSS3: 7.8
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.8
debian
почти 6 лет назад

OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an expe ...

CVSS3: 7.8
github
больше 3 лет назад

OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and remote code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.

EPSS

Процентиль: 32%
0.00123
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-190