Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3860

Опубликовано: 13 мар. 2019
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

An out of bounds read flaw was discovered in libssh2 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a denial of service or read data in the client memory.

Отчет

This flaw was present in libssh2 packages included in Red Hat Virtualization Hypervisor and Management Appliance, however libssh2 in these hosts is never exposed to malicious clients or servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libssh2Will not fix
Red Hat Enterprise Linux 7libssh2Will not fix
Red Hat Enterprise Linux 8virt:rhel/libssh2Will not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.0.0/libssh2Not affected
Red Hat Virtualization 4redhat-virtualization-hostWill not fix
Red Hat Virtualization 4rhvm-applianceWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1687310libssh2: Out-of-bounds reads with specially crafted SFTP packets

EPSS

Процентиль: 91%
0.04496
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
больше 7 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

CVSS3: 5
nvd
больше 7 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

CVSS3: 5
debian
больше 7 лет назад

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in t ...

suse-cvrf
около 7 лет назад

Security update for libssh2_org

suse-cvrf
около 7 лет назад

Security update for libssh2_org

EPSS

Процентиль: 91%
0.04496
Низкий

5 Medium

CVSS3