Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-1884

Опубликовано: 30 июл. 2019
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2019-1884: libssh2 security update (MODERATE)

[1.4.3-12.0.1.el7_6.3]

  • Bump and rebuild.

[1.4.3-12.el7_6.3]

  • fix out-of-bounds memory comparison with specially crafted message channel request (CVE-2019-3862)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

libssh2

1.4.3-12.0.1.el7_6.3

libssh2-devel

1.4.3-12.0.1.el7_6.3

libssh2-docs

1.4.3-12.0.1.el7_6.3

Oracle Linux x86_64

libssh2

1.4.3-12.0.1.el7_6.3

libssh2-devel

1.4.3-12.0.1.el7_6.3

libssh2-docs

1.4.3-12.0.1.el7_6.3

Связанные CVE

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 7 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

CVSS3: 7.3
redhat
почти 7 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

CVSS3: 7.3
nvd
почти 7 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

CVSS3: 7.3
debian
почти 7 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in t ...

CVSS3: 9.1
github
больше 3 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.