CVE-2020-22218Out-of-bounds Write in Libssh2

Severity
7.5HIGHNVD
EPSS
0.1%
top 76.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 22
Latest updateApr 15

Description

An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

debiandebian/libssh2< libssh2 1.10.0-2 (bookworm)
Debianlibssh2/libssh2< 1.9.0-2+deb11u1+3
NVDlibssh2/libssh21.10.0

Patches

🔴Vulnerability Details

2
OSV
CVE-2020-22218: An issue was discovered in function _libssh2_packet_add in libssh2 12023-08-22
GHSA
GHSA-4wvm-v4fc-prp5: An issue was discovered in function _libssh2_packet_add in libssh2 12023-08-22

📋Vendor Advisories

7
CISA ICS
ABB M2M Gateway2025-04-15
Oracle
Oracle Oracle PeopleSoft Risk Matrix: File Processing (libssh2) — CVE-2020-222182025-01-15
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.12023-12-14
Ubuntu
libssh2 vulnerability2023-09-14
Red Hat
libssh2: use-of-uninitialized-value in _libssh2_transport_read2023-08-22