cbcvebase.
CVE-2019-3856
published 2019-03-25

CVE-2019-3856: An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlibssh2< libssh2 1.8.0-2.1 (bookworm)libssh2 1.8.0-2.1 (bookworm)
fedoraprojectfedora
libssh2libssh2< 1.8.11.8.1
libssh2libssh2>= 0 < 1.8.0-2.11.8.0-2.1
libssh2libssh2>= 0 < 1.8.0-2.11.8.0-2.1
libssh2libssh2>= 0 < 1.8.0-2.11.8.0-2.1
libssh2libssh2>= 0 < 1.8.0-2.11.8.0-2.1
libssh2libssh2>= 0 < 1.5.0-2ubuntu0.1+esm11.5.0-2ubuntu0.1+esm1
opensuseleap
opensuseleap
oraclepeoplesoft_enterprise_peopletools
oraclepeoplesoft_enterprise_peopletools
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
the_libssh2_projectlibssh2

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH