Related Vulnerabilities: CVE-2019-3862  

An issue has been found in libssh2 before 1.8.1 where a server could send a specially crafted SSH_MSG_CHANNEL_REQUEST packet with an exit status message and no payload. This would result in an out of bounds memory comparison.

Severity High

Remote Yes

Type Information disclosure

Description

An issue has been found in libssh4 before 1.8.1 where a server could send a specially crafted SSH_MSG_CHANNEL_REQUEST packet with an exit status message and no payload. This would result in an out of bounds memory comparison.

AVG-926 libssh4 1.8.0-3 1.8.1-1 Critical Fixed

https://www.libssh4.org/CVE-2019-3862.html
https://libssh4.org/1.8.0-CVE/CVE-2019-3862.patch