Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-4693

Опубликовано: 20 июн. 2019
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2019-4693: libssh2 security update (IMPORTANT)

[1.4.2-2.0.1.el6_7.1]

  • [Orabug: 29909723] Added patch CVE-2019-3862. Added Additional length checks to prevent out-of-bounds (CVE-2019-3862)

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

libssh2

1.4.2-2.0.1.el6_7.1

libssh2-devel

1.4.2-2.0.1.el6_7.1

libssh2-docs

1.4.2-2.0.1.el6_7.1

Oracle Linux i686

libssh2

1.4.2-2.0.1.el6_7.1

libssh2-devel

1.4.2-2.0.1.el6_7.1

libssh2-docs

1.4.2-2.0.1.el6_7.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 7 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

CVSS3: 7.3
redhat
почти 7 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

CVSS3: 7.3
nvd
почти 7 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

CVSS3: 7.3
debian
почти 7 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in t ...

CVSS3: 9.1
github
больше 3 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.