CVE-2019-3863
published 2019-03-25CVE-2019-3863: A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages…
PriorityP344high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
3.44%
87.7th percentile
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used by the SSH client as an index to copy memory causing in an out of bounds memory write error.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libssh2 | < libssh2 1.8.0-2.1 (bookworm) | libssh2 1.8.0-2.1 (bookworm) |
| libssh2 | libssh2 | < 1.8.1 | 1.8.1 |
| libssh2 | libssh2 | >= 0 < 1.8.0-2.1 | 1.8.0-2.1 |
| libssh2 | libssh2 | >= 0 < 1.8.0-2.1 | 1.8.0-2.1 |
| libssh2 | libssh2 | >= 0 < 1.8.0-2.1 | 1.8.0-2.1 |
| libssh2 | libssh2 | >= 0 < 1.8.0-2.1 | 1.8.0-2.1 |
| libssh2 | libssh2 | >= 0 < 1.5.0-2ubuntu0.1+esm1 | 1.5.0-2ubuntu0.1+esm1 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| the_libssh2_project | libssh2 | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_ubuntu8.1HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
libssh2 vulnerabilities
vendor_ubuntu·2022-03-07·CVSS 8.1
CVE-2019-3863 [HIGH] libssh2 vulnerabilities
Title: libssh2 vulnerabilities
Summary: Several security issues were fixed in libssh2.
It was discovered that libssh2 mishandled certain input. If libssh2 were
used to connect to a malicious or compromised SSH server, a remote,
unauthenticated attacker could possibly execute arbitrary code on the client
system. (CVE-2019-3855)
It was discovered that libssh2 incorrectly handled prompt requests. A
remote attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-3856)
It was discovered that libssh2 incorrectly handled SSH_MSG_CHANNEL_REQUEST
packets. A remote attacker could possibly use this issue to execute
arbitrary code, cause a denial of service, or obtain sensitive information.
(CVE-2019-3857, CVE-2019-3862)
It was discovered that libssh2 incorrectly handled specia
Red Hat
libssh2: Integer overflow in user authenticate keyboard interactive allows out-of-bounds writes
vendor_redhat·2019-03-13·CVSS 7.5
CVE-2019-3863 [HIGH] CWE-190 libssh2: Integer overflow in user authenticate keyboard interactive allows out-of-bounds writes
libssh2: Integer overflow in user authenticate keyboard interactive allows out-of-bounds writes
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used by the SSH client as an index to copy memory causing in an out of bounds memory write error.
A flaw was found in libssh2. A server could send a multiple keyboard interactive response messages, whose total length are greater than the unsigned char max characters. This value is used as an index to copy memory causing in an out of bounds memory write error. The highest threat from this vulnerability is to data confidentiality and integrity and system avail
Debian
CVE-2019-3863: libssh2 - A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH cli...
vendor_debian·2019·CVSS 7.5
CVE-2019-3863 [HIGH] CVE-2019-3863: libssh2 - A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH cli...
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used by the SSH client as an index to copy memory causing in an out of bounds memory write error.
Scope: local
bookworm: resolved (fixed in 1.8.0-2.1)
bullseye: resolved (fixed in 1.8.0-2.1)
forky: resolved (fixed in 1.8.0-2.1)
sid: resolved (fixed in 1.8.0-2.1)
trixie: resolved (fixed in 1.8.0-2.1)
GHSA
GHSA-h63q-2463-x5hq: A flaw was found in libssh2 before 1
ghsa_unreviewed·2022-05-14
CVE-2019-3863 [HIGH] CWE-190 GHSA-h63q-2463-x5hq: A flaw was found in libssh2 before 1
A flaw was found in libssh2 before 1.8.1. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used as an index to copy memory causing in an out of bounds memory write error.
OSV
libssh2 vulnerabilities
osv·2022-03-07·CVSS 8.1
CVE-2019-3855 [HIGH] libssh2 vulnerabilities
libssh2 vulnerabilities
It was discovered that libssh2 mishandled certain input. If libssh2 were
used to connect to a malicious or compromised SSH server, a remote,
unauthenticated attacker could possibly execute arbitrary code on the client
system. (CVE-2019-3855)
It was discovered that libssh2 incorrectly handled prompt requests. A
remote attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-3856)
It was discovered that libssh2 incorrectly handled SSH_MSG_CHANNEL_REQUEST
packets. A remote attacker could possibly use this issue to execute
arbitrary code, cause a denial of service, or obtain sensitive information.
(CVE-2019-3857, CVE-2019-3862)
It was discovered that libssh2 incorrectly handled specially crafted SFTP
packets. A remote attacker could possibly use t
OSV
CVE-2019-3863: A flaw was found in libssh2 before 1
osv·2019-03-25·CVSS 8.8
CVE-2019-3863 [HIGH] CVE-2019-3863: A flaw was found in libssh2 before 1
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used by the SSH client as an index to copy memory causing in an out of bounds memory write error.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [fedora-all]
bugzilla·2019-03-19·CVSS 8.8
CVE-2019-3855 [HIGH] CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [fedora-all]
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM chan
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [epel-7]
bugzilla·2019-03-19·CVSS 8.8
CVE-2019-3855 [HIGH] CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [epel-7]
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 mingw-libssh2: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog an
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh2: various flaws [fedora-all]
bugzilla·2019-03-19·CVSS 8.8
CVE-2019-3855 [HIGH] CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh2: various flaws [fedora-all]
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog
Bugzilla
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh: various flaws [fedora-all]
bugzilla·2019-03-19·CVSS 8.8
CVE-2019-3855 [HIGH] CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh: various flaws [fedora-all]
CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 libssh: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog a
Bugzilla
CVE-2019-3863 libssh2: Integer overflow in user authenticate keyboard interactive allows out-of-bounds writes
bugzilla·2019-03-11·CVSS 7.5
CVE-2019-3863 [HIGH] CVE-2019-3863 libssh2: Integer overflow in user authenticate keyboard interactive allows out-of-bounds writes
CVE-2019-3863 libssh2: Integer overflow in user authenticate keyboard interactive allows out-of-bounds writes
A server could send a multiple keyboard interactive response messages whose
total length are greater than unsigned char max characters. This value is
used as an index to copy memory causing in an out of bounds memory write error.
Discussion:
Acknowledgments:
Name: the libssh2 project
Upstream: Chris Coulson (Canonical Ltd.)
---
Function userauth_keyboard_interactive() in userauth.c sums a set of values without checking for integer overflow. The result is then used to allocate memory and to copy attacker-controlled strings later on. If the integer overflow happens, writes can happen out of bounds, possibly allowing an attacker to execute code remotely.
---
The attacker needs
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlhttps://access.redhat.com/errata/RHSA-2019:0679https://access.redhat.com/errata/RHSA-2019:1175https://access.redhat.com/errata/RHSA-2019:1652https://access.redhat.com/errata/RHSA-2019:1791https://access.redhat.com/errata/RHSA-2019:1943https://access.redhat.com/errata/RHSA-2019:2399https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3863https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5DK6VO2CEUTAJFYIKWNZKEKYMYR3NO2O/https://seclists.org/bugtraq/2019/Apr/25https://security.netapp.com/advisory/ntap-20190327-0005/https://www.debian.org/security/2019/dsa-4431https://www.libssh2.org/CVE-2019-3863.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlhttps://access.redhat.com/errata/RHSA-2019:0679https://access.redhat.com/errata/RHSA-2019:1175https://access.redhat.com/errata/RHSA-2019:1652https://access.redhat.com/errata/RHSA-2019:1791https://access.redhat.com/errata/RHSA-2019:1943https://access.redhat.com/errata/RHSA-2019:2399https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3863https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5DK6VO2CEUTAJFYIKWNZKEKYMYR3NO2O/https://seclists.org/bugtraq/2019/Apr/25https://security.netapp.com/advisory/ntap-20190327-0005/https://www.debian.org/security/2019/dsa-4431https://www.libssh2.org/CVE-2019-3863.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2019-03-25
Published