CVE-2019-3859Out-of-bounds Read in Libssh2

CWE-125Out-of-bounds Read12 documents8 sources
Severity
9.1CRITICALNVD
EPSS
1.2%
top 21.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 21
Latest updateMay 14

Description

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages4 packages

NVDlibssh2/libssh2< 1.8.1
Debianlibssh2/libssh2< 1.8.0-2.1+3
NVDopensuse/leap15.0, 42.3+1

Also affects: Debian Linux 8.0, 9.0, Fedora 28, 29

Patches

🔴Vulnerability Details

3
GHSA
GHSA-3fjx-35vx-pq97: An out of bounds read flaw was discovered in libssh2 before 12022-05-14
OSV
CVE-2019-3859: An out of bounds read flaw was discovered in libssh2 before 12019-03-21
CVEList
CVE-2019-3859: An out of bounds read flaw was discovered in libssh2 before 12019-03-20

📋Vendor Advisories

3
Ubuntu
libssh2 vulnerabilities2022-03-07
Red Hat
libssh2: Unchecked use of _libssh2_packet_require and _libssh2_packet_requirev resulting in out-of-bounds read2019-03-13
Debian
CVE-2019-3859: libssh2 - An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh...2019

💬Community

5
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [fedora-all]2019-03-19
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [epel-7]2019-03-19
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh2: various flaws [fedora-all]2019-03-19
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh: various flaws [fedora-all]2019-03-19
Bugzilla
CVE-2019-3859 libssh2: Unchecked use of _libssh2_packet_require and _libssh2_packet_requirev resulting in out-of-bounds read2019-03-11
CVE-2019-3859 — Out-of-bounds Read in Libssh2 | cvebase