cbcvebase.
CVE-2019-3858
published 2019-03-21

CVE-2019-3858: An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who…

PriorityP351critical9.1CVSS 3.0
AVNACLPRNUINSUCHINAH
EPSS
6.45%
93.0th percentile
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibssh2< libssh2 1.8.0-2.1 (bookworm)libssh2 1.8.0-2.1 (bookworm)
fedoraprojectfedora
libssh2libssh2< 1.8.11.8.1
libssh2libssh2>= 0 < 1.8.0-2.11.8.0-2.1
libssh2libssh2>= 0 < 1.8.0-2.11.8.0-2.1
libssh2libssh2>= 0 < 1.8.0-2.11.8.0-2.1
libssh2libssh2>= 0 < 1.8.0-2.11.8.0-2.1
libssh2libssh2>= 0 < 1.5.0-2ubuntu0.1+esm11.5.0-2ubuntu0.1+esm1
opensuseleap
opensuseleap
the_libssh2_projectlibssh2

CVSS provenance

nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.1CRITICAL
vendor_ubuntu8.1HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.