CVE-2019-3860Out-of-bounds Read in Libssh2

CWE-125Out-of-bounds Read12 documents8 sources
Severity
9.1CRITICALNVD
CNA5.0
EPSS
1.0%
top 23.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMay 14

Description

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages4 packages

Debianlibssh2/libssh2< 1.8.0-2.1+3
NVDlibssh2/libssh20.31.8.0
NVDopensuse/leap15.0, 42.3+1

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fq9v-3w7w-rvm2: An out of bounds read flaw was discovered in libssh2 before 12022-05-14
CVEList
CVE-2019-3860: An out of bounds read flaw was discovered in libssh2 before 12019-03-25
OSV
CVE-2019-3860: An out of bounds read flaw was discovered in libssh2 before 12019-03-25

📋Vendor Advisories

3
Ubuntu
libssh2 vulnerabilities2022-03-07
Red Hat
libssh2: Out-of-bounds reads with specially crafted SFTP packets2019-03-13
Debian
CVE-2019-3860: libssh2 - An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFT...2019

💬Community

5
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [fedora-all]2019-03-19
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [epel-7]2019-03-19
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh2: various flaws [fedora-all]2019-03-19
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh: various flaws [fedora-all]2019-03-19
Bugzilla
CVE-2019-3860 libssh2: Out-of-bounds reads with specially crafted SFTP packets2019-03-11
CVE-2019-3860 — Out-of-bounds Read in Libssh2 | cvebase