Severity
8.8HIGH
EPSS
8.6%
top 7.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMay 14

Description

A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used by the SSH client as an index to copy memory causing in an out of bounds memory write error.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages7 packages

NVDlibssh2/libssh2< 1.8.1
Debianlibssh2< 1.8.0-2.1+3
NVDopensuse/leap15.0, 42.3+1

Also affects: Debian Linux 8.0, Enterprise Linux 7.6

Patches

🔴Vulnerability Details

3
GHSA
GHSA-h63q-2463-x5hq: A flaw was found in libssh2 before 12022-05-14
OSV
CVE-2019-3863: A flaw was found in libssh2 before 12019-03-25
CVEList
CVE-2019-3863: A flaw was found in libssh2 before 12019-03-25

📋Vendor Advisories

3
Ubuntu
libssh2 vulnerabilities2022-03-07
Red Hat
libssh2: Integer overflow in user authenticate keyboard interactive allows out-of-bounds writes2019-03-13
Debian
CVE-2019-3863: libssh2 - A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH cli...2019

💬Community

5
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [fedora-all]2019-03-19
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [epel-7]2019-03-19
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh2: various flaws [fedora-all]2019-03-19
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh: various flaws [fedora-all]2019-03-19
Bugzilla
CVE-2019-3863 libssh2: Integer overflow in user authenticate keyboard interactive allows out-of-bounds writes2019-03-11
CVE-2019-3863 (HIGH CVSS 8.8) | A flaw was found in libssh2 before | cvebase.io