CVE-2019-3858
published 2019-03-21CVE-2019-3858: An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who…
PriorityP351critical9.1CVSS 3.0
AVNACLPRNUINSUCHINAH
EPSS
6.45%
93.0th percentile
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libssh2 | < libssh2 1.8.0-2.1 (bookworm) | libssh2 1.8.0-2.1 (bookworm) |
| fedoraproject | fedora | — | — |
| libssh2 | libssh2 | < 1.8.1 | 1.8.1 |
| libssh2 | libssh2 | >= 0 < 1.8.0-2.1 | 1.8.0-2.1 |
| libssh2 | libssh2 | >= 0 < 1.8.0-2.1 | 1.8.0-2.1 |
| libssh2 | libssh2 | >= 0 < 1.8.0-2.1 | 1.8.0-2.1 |
| libssh2 | libssh2 | >= 0 < 1.8.0-2.1 | 1.8.0-2.1 |
| libssh2 | libssh2 | >= 0 < 1.5.0-2ubuntu0.1+esm1 | 1.5.0-2ubuntu0.1+esm1 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| the_libssh2_project | libssh2 | — | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.1CRITICAL
vendor_ubuntu8.1HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
libssh2 vulnerabilities
vendor_ubuntu·2022-03-07·CVSS 8.1
CVE-2019-3863 [HIGH] libssh2 vulnerabilities
Title: libssh2 vulnerabilities
Summary: Several security issues were fixed in libssh2.
It was discovered that libssh2 mishandled certain input. If libssh2 were
used to connect to a malicious or compromised SSH server, a remote,
unauthenticated attacker could possibly execute arbitrary code on the client
system. (CVE-2019-3855)
It was discovered that libssh2 incorrectly handled prompt requests. A
remote attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-3856)
It was discovered that libssh2 incorrectly handled SSH_MSG_CHANNEL_REQUEST
packets. A remote attacker could possibly use this issue to execute
arbitrary code, cause a denial of service, or obtain sensitive information.
(CVE-2019-3857, CVE-2019-3862)
It was discovered that libssh2 incorrectly handled specia
Red Hat
libssh2: Zero-byte allocation with a specially crafted SFTP packed leading to an out-of-bounds read
vendor_redhat·2019-03-13·CVSS 5.0
CVE-2019-3858 [MEDIUM] CWE-125 libssh2: Zero-byte allocation with a specially crafted SFTP packed leading to an out-of-bounds read
libssh2: Zero-byte allocation with a specially crafted SFTP packed leading to an out-of-bounds read
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
An out of bounds read flaw was discovered in libssh2 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a denial of service or read data in the client memory.
Statement: This flaw was present in libssh2 packages included in Red Hat Virtualization Hypervisor and Management Appliance, however libssh2 in these hosts is never exposed to malicious clients or ser
Debian
CVE-2019-3858: libssh2 - An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a special...
vendor_debian·2019·CVSS 5.0
CVE-2019-3858 [MEDIUM] CVE-2019-3858: libssh2 - An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a special...
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
Scope: local
bookworm: resolved (fixed in 1.8.0-2.1)
bullseye: resolved (fixed in 1.8.0-2.1)
forky: resolved (fixed in 1.8.0-2.1)
sid: resolved (fixed in 1.8.0-2.1)
trixie: resolved (fixed in 1.8.0-2.1)
GHSA
GHSA-c4h5-vgqh-28mg: An out of bounds read flaw was discovered in libssh2 before 1
ghsa_unreviewed·2022-05-14
CVE-2019-3858 [CRITICAL] CWE-125 GHSA-c4h5-vgqh-28mg: An out of bounds read flaw was discovered in libssh2 before 1
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
OSV
libssh2 vulnerabilities
osv·2022-03-07·CVSS 8.1
CVE-2019-3855 [HIGH] libssh2 vulnerabilities
libssh2 vulnerabilities
It was discovered that libssh2 mishandled certain input. If libssh2 were
used to connect to a malicious or compromised SSH server, a remote,
unauthenticated attacker could possibly execute arbitrary code on the client
system. (CVE-2019-3855)
It was discovered that libssh2 incorrectly handled prompt requests. A
remote attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-3856)
It was discovered that libssh2 incorrectly handled SSH_MSG_CHANNEL_REQUEST
packets. A remote attacker could possibly use this issue to execute
arbitrary code, cause a denial of service, or obtain sensitive information.
(CVE-2019-3857, CVE-2019-3862)
It was discovered that libssh2 incorrectly handled specially crafted SFTP
packets. A remote attacker could possibly use t
OSV
CVE-2019-3858: An out of bounds read flaw was discovered in libssh2 before 1
osv·2019-03-21·CVSS 9.1
CVE-2019-3858 [CRITICAL] CVE-2019-3858: An out of bounds read flaw was discovered in libssh2 before 1
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [fedora-all]
bugzilla·2019-03-19·CVSS 8.8
CVE-2019-3855 [HIGH] CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [fedora-all]
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM chan
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [epel-7]
bugzilla·2019-03-19·CVSS 8.8
CVE-2019-3855 [HIGH] CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [epel-7]
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog an
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh2: various flaws [fedora-all]
bugzilla·2019-03-19·CVSS 8.8
CVE-2019-3855 [HIGH] CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh2: various flaws [fedora-all]
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh: various flaws [fedora-all]
bugzilla·2019-03-19·CVSS 8.8
CVE-2019-3855 [HIGH] CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh: various flaws [fedora-all]
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog a
Bugzilla
CVE-2019-3858 libssh2: Zero-byte allocation with a specially crafted SFTP packed leading to an out-of-bounds read
bugzilla·2019-03-11·CVSS 5.0
CVE-2019-3858 [MEDIUM] CVE-2019-3858 libssh2: Zero-byte allocation with a specially crafted SFTP packed leading to an out-of-bounds read
CVE-2019-3858 libssh2: Zero-byte allocation with a specially crafted SFTP packed leading to an out-of-bounds read
A server could send a specially crafted partial SFTP packet with a zero value
for the payload length. This zero value would be used to then allocate memory
resulting in a zero byte allocation and possible out of bounds read.
Discussion:
Acknowledgments:
Name: the libssh2 project
Upstream: Chris Coulson (Canonical Ltd.)
---
Function sftp_packet_read() in sftp.c does not check if partial_len is zero and it is vulnerable to an out-of-bounds read.
---
Reference:
https://www.openwall.com/lists/oss-security/2019/03/18/3
Upstream Patch:
https://libssh2.org/1.8.0-CVE/CVE-2019-3858.patch
---
External References:
https://www.libssh2.org/CVE-2019-3858.html
---
Created libssh
Bugzilla
CVE-2012-4386 struts2: CSRF protection bypass
bugzilla·2012-09-03·CVSS 6.8
CVE-2012-4386 [MEDIUM] CVE-2012-4386 struts2: CSRF protection bypass
CVE-2012-4386 struts2: CSRF protection bypass
Apache Struts2 includes CSRF protection based on an implementation of the synchronizer token pattern. It was found that this protection could be bypassed by an attacker changing the token name configuration parameter to match a session attribute known to the attacker. Struts 2.0.0 to Struts 2.3.4 is affected by this flaw. It is resolved in Struts 2.3.4.1.
Upstream advisory:
http://struts.apache.org/2.x/docs/s2-010.html
Discussion:
References:
https://issues.apache.org/jira/browse/WW-3858
http://www.securityfocus.com/bid/55346
http://secunia.com/advisories/50420
http://xforce.iss.net/xforce/xfdb/78182
---
Statement:
A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlhttp://packetstormsecurity.com/files/152136/Slackware-Security-Advisory-libssh2-Updates.htmlhttp://www.openwall.com/lists/oss-security/2019/03/18/3http://www.securityfocus.com/bid/107485https://access.redhat.com/errata/RHSA-2019:2136https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3858https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5DK6VO2CEUTAJFYIKWNZKEKYMYR3NO2O/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCWEA5ZCLKRDUK62QVVYMFWLWKOPX3LO/https://seclists.org/bugtraq/2019/Apr/25https://seclists.org/bugtraq/2019/Mar/25https://security.netapp.com/advisory/ntap-20190327-0005/https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-767https://www.debian.org/security/2019/dsa-4431https://www.libssh2.org/CVE-2019-3858.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlhttp://packetstormsecurity.com/files/152136/Slackware-Security-Advisory-libssh2-Updates.htmlhttp://www.openwall.com/lists/oss-security/2019/03/18/3http://www.securityfocus.com/bid/107485https://access.redhat.com/errata/RHSA-2019:2136https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3858https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5DK6VO2CEUTAJFYIKWNZKEKYMYR3NO2O/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCWEA5ZCLKRDUK62QVVYMFWLWKOPX3LO/https://seclists.org/bugtraq/2019/Apr/25https://seclists.org/bugtraq/2019/Mar/25https://security.netapp.com/advisory/ntap-20190327-0005/https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-767https://www.debian.org/security/2019/dsa-4431https://www.libssh2.org/CVE-2019-3858.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2019-03-21
Published