Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-17498

Опубликовано: 16 окт. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server.

Отчет

This flaw needs a malicious MITM SSH server. When an application compiled with libssh2 connects to such a MITM SSH server, the server can trigger an integer overflow leading to an OOB read in the SSH_MSG_DISCONNECT logic. This can cause the application compiled with libssh2 to crash. This is strictly a client side crash and the SSH server may not be affected. Also note that when a user connects to a malicious MITM server there is already a risk of disclosing password/keys irrespective of the flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libssh2Out of support scope
Red Hat Enterprise Linux 8virt:rhel/libssh2Not affected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.0/libssh2Will not fix
Red Hat Enterprise Linux 7libssh2FixedRHSA-2020:391529.09.2020
Red Hat OpenShift Doopenshiftdo/odo-init-image-rhel7FixedRHSA-2021:094922.03.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
Дефект:
CWE-200
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1766898libssh2: integer overflow in SSH_MSG_DISCONNECT logic in packet.c

EPSS

Процентиль: 84%
0.02198
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 6 лет назад

In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server.

CVSS3: 8.1
nvd
почти 6 лет назад

In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server.

CVSS3: 8.1
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 8.1
debian
почти 6 лет назад

In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic i ...

suse-cvrf
почти 6 лет назад

Security update for libssh2_org

EPSS

Процентиль: 84%
0.02198
Низкий

6.5 Medium

CVSS3