cbcvebase.
CVE-2019-3861
published 2019-03-25

CVE-2019-3861: An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed…

PriorityP347critical9.1CVSS 3.0
AVNACLPRNUINSUCHINAH
EPSS
5.12%
91.4th percentile
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibssh2< libssh2 1.8.0-2.1 (bookworm)libssh2 1.8.0-2.1 (bookworm)
libssh2libssh2>= 0 < 1.8.0-2.11.8.0-2.1
libssh2libssh2>= 0 < 1.8.0-2.11.8.0-2.1
libssh2libssh2>= 0 < 1.8.0-2.11.8.0-2.1
libssh2libssh2>= 0 < 1.8.0-2.11.8.0-2.1
libssh2libssh2>= 0 < 1.5.0-2ubuntu0.1+esm11.5.0-2ubuntu0.1+esm1
libssh2libssh20.15 – 1.8.0
opensuseleap
opensuseleap
the_libssh2_projectlibssh2

CVSS provenance

nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.1CRITICAL
vendor_ubuntu8.1HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.