CVE-2019-3856
published 2019-03-25CVE-2019-3856: An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A…
PriorityP351high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
6.13%
92.7th percentile
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libssh2 | < libssh2 1.8.0-2.1 (bookworm) | libssh2 1.8.0-2.1 (bookworm) |
| fedoraproject | fedora | — | — |
| libssh2 | libssh2 | < 1.8.1 | 1.8.1 |
| libssh2 | libssh2 | >= 0 < 1.8.0-2.1 | 1.8.0-2.1 |
| libssh2 | libssh2 | >= 0 < 1.8.0-2.1 | 1.8.0-2.1 |
| libssh2 | libssh2 | >= 0 < 1.8.0-2.1 | 1.8.0-2.1 |
| libssh2 | libssh2 | >= 0 < 1.8.0-2.1 | 1.8.0-2.1 |
| libssh2 | libssh2 | >= 0 < 1.5.0-2ubuntu0.1+esm1 | 1.5.0-2ubuntu0.1+esm1 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| the_libssh2_project | libssh2 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
libssh2 vulnerabilities
vendor_ubuntu·2022-03-07·CVSS 8.1
CVE-2019-3863 [HIGH] libssh2 vulnerabilities
Title: libssh2 vulnerabilities
Summary: Several security issues were fixed in libssh2.
It was discovered that libssh2 mishandled certain input. If libssh2 were
used to connect to a malicious or compromised SSH server, a remote,
unauthenticated attacker could possibly execute arbitrary code on the client
system. (CVE-2019-3855)
It was discovered that libssh2 incorrectly handled prompt requests. A
remote attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-3856)
It was discovered that libssh2 incorrectly handled SSH_MSG_CHANNEL_REQUEST
packets. A remote attacker could possibly use this issue to execute
arbitrary code, cause a denial of service, or obtain sensitive information.
(CVE-2019-3857, CVE-2019-3862)
It was discovered that libssh2 incorrectly handled specia
Red Hat
libssh2: Integer overflow in keyboard interactive handling resulting in out of bounds write
vendor_redhat·2019-03-13·CVSS 8.8
CVE-2019-3856 [HIGH] CWE-190 libssh2: Integer overflow in keyboard interactive handling resulting in out of bounds write
libssh2: Integer overflow in keyboard interactive handling resulting in out of bounds write
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
Statement: This flaw was present in libssh2 packages included in Red Hat Virtualization Hypervisor and Management Appliance, however libssh2
Debian
CVE-2019-3856: libssh2 - An integer overflow flaw, which could lead to an out of bounds write, was discov...
vendor_debian·2019·CVSS 8.8
CVE-2019-3856 [HIGH] CVE-2019-3856: libssh2 - An integer overflow flaw, which could lead to an out of bounds write, was discov...
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
Scope: local
bookworm: resolved (fixed in 1.8.0-2.1)
bullseye: resolved (fixed in 1.8.0-2.1)
forky: resolved (fixed in 1.8.0-2.1)
sid: resolved (fixed in 1.8.0-2.1)
trixie: resolved (fixed in 1.8.0-2.1)
GHSA
GHSA-w4mw-p8mf-732j: An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1
ghsa_unreviewed·2022-05-13
CVE-2019-3856 [HIGH] CWE-787 GHSA-w4mw-p8mf-732j: An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
OSV
libssh2 vulnerabilities
osv·2022-03-07·CVSS 8.1
CVE-2019-3855 [HIGH] libssh2 vulnerabilities
libssh2 vulnerabilities
It was discovered that libssh2 mishandled certain input. If libssh2 were
used to connect to a malicious or compromised SSH server, a remote,
unauthenticated attacker could possibly execute arbitrary code on the client
system. (CVE-2019-3855)
It was discovered that libssh2 incorrectly handled prompt requests. A
remote attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-3856)
It was discovered that libssh2 incorrectly handled SSH_MSG_CHANNEL_REQUEST
packets. A remote attacker could possibly use this issue to execute
arbitrary code, cause a denial of service, or obtain sensitive information.
(CVE-2019-3857, CVE-2019-3862)
It was discovered that libssh2 incorrectly handled specially crafted SFTP
packets. A remote attacker could possibly use t
OSV
CVE-2019-3856: An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1
osv·2019-03-25·CVSS 8.8
CVE-2019-3856 [HIGH] CVE-2019-3856: An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [fedora-all]
bugzilla·2019-03-19·CVSS 8.8
CVE-2019-3855 [HIGH] CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [fedora-all]
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM chan
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [epel-7]
bugzilla·2019-03-19·CVSS 8.8
CVE-2019-3855 [HIGH] CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [epel-7]
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog an
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh2: various flaws [fedora-all]
bugzilla·2019-03-19·CVSS 8.8
CVE-2019-3855 [HIGH] CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh2: various flaws [fedora-all]
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh: various flaws [fedora-all]
bugzilla·2019-03-19·CVSS 8.8
CVE-2019-3855 [HIGH] CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh: various flaws [fedora-all]
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog a
Bugzilla
CVE-2019-3856 libssh2: Integer overflow in keyboard interactive handling resulting in out of bounds write
bugzilla·2019-03-11·CVSS 8.8
CVE-2019-3856 [HIGH] CVE-2019-3856 libssh2: Integer overflow in keyboard interactive handling resulting in out of bounds write
CVE-2019-3856 libssh2: Integer overflow in keyboard interactive handling resulting in out of bounds write
A server could send a value approching unsinged int max number of keyboard
prompt requests which could result in an unchecked interger overflow. The value
would then be used to allocate memory causing a possible memory write out of
bounds error.
Discussion:
Acknowledgments:
Name: the libssh2 project
Upstream: Chris Coulson (Canonical Ltd.)
---
Function userauth_keyboard_interactive() in userauth.c does not properly check the number of prompts sent by the server and it uses the value in a computation that could result in an integer overflow. The result would then be used to allocate memory and can allow writing beyond the limits of the allocated buffer.
---
The attacker needs to
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlhttps://access.redhat.com/errata/RHSA-2019:0679https://access.redhat.com/errata/RHSA-2019:1175https://access.redhat.com/errata/RHSA-2019:1652https://access.redhat.com/errata/RHSA-2019:1791https://access.redhat.com/errata/RHSA-2019:1943https://access.redhat.com/errata/RHSA-2019:2399https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3856https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5DK6VO2CEUTAJFYIKWNZKEKYMYR3NO2O/https://seclists.org/bugtraq/2019/Apr/25https://security.netapp.com/advisory/ntap-20190327-0005/https://www.debian.org/security/2019/dsa-4431https://www.libssh2.org/CVE-2019-3856.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlhttps://access.redhat.com/errata/RHSA-2019:0679https://access.redhat.com/errata/RHSA-2019:1175https://access.redhat.com/errata/RHSA-2019:1652https://access.redhat.com/errata/RHSA-2019:1791https://access.redhat.com/errata/RHSA-2019:1943https://access.redhat.com/errata/RHSA-2019:2399https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3856https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5DK6VO2CEUTAJFYIKWNZKEKYMYR3NO2O/https://seclists.org/bugtraq/2019/Apr/25https://security.netapp.com/advisory/ntap-20190327-0005/https://www.debian.org/security/2019/dsa-4431https://www.libssh2.org/CVE-2019-3856.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2019-03-25
Published