Количество 12
Количество 12
GHSA-3wqh-87fg-ffgg
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.
CVE-2025-15661
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.
CVE-2025-15661
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.
CVE-2025-15661
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation.
CVE-2025-15661
libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c
CVE-2025-15661
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bo ...
ROS-20260810-80-0019
Уязвимость libssh2
ROS-20260810-73-0032
Уязвимость libssh2
openSUSE-SU-2026:21549-1
Security update for libssh2_org
SUSE-SU-2026:3541-1
Security update for libssh2_org
SUSE-SU-2026:3526-1
Security update for libssh2_org
SUSE-SU-2026:3525-1
Security update for libssh2_org
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3wqh-87fg-ffgg libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2025-15661 libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2025-15661 libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2025-15661 libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2025-15661 libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c | CVSS3: 6.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2025-15661 libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bo ... | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
ROS-20260810-80-0019 Уязвимость libssh2 | CVSS3: 6.5 | 1% Низкий | 10 дней назад | |
ROS-20260810-73-0032 Уязвимость libssh2 | CVSS3: 6.5 | 1% Низкий | 10 дней назад | |
openSUSE-SU-2026:21549-1 Security update for libssh2_org | 9 дней назад | |||
SUSE-SU-2026:3541-1 Security update for libssh2_org | 9 дней назад | |||
SUSE-SU-2026:3526-1 Security update for libssh2_org | 12 дней назад | |||
SUSE-SU-2026:3525-1 Security update for libssh2_org | 12 дней назад |
Уязвимостей на страницу