Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-17498

Опубликовано: 21 окт. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.8
CVSS3: 8.1

Описание

In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1.9.0-1
disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

not-affected

1.9.0-1
esm-apps/xenial

released

1.5.0-2ubuntu0.1+esm1
esm-infra-legacy/trusty

released

1.4.3-2ubuntu0.2+esm2
focal

ignored

end of standard support, was needed

Показывать по

EPSS

Процентиль: 79%
0.01252
Низкий

5.8 Medium

CVSS2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
почти 6 лет назад

In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server.

CVSS3: 8.1
nvd
почти 6 лет назад

In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server.

CVSS3: 8.1
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 8.1
debian
почти 6 лет назад

In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic i ...

suse-cvrf
почти 6 лет назад

Security update for libssh2_org

EPSS

Процентиль: 79%
0.01252
Низкий

5.8 Medium

CVSS2

8.1 High

CVSS3