572
VMScore

CVE-2019-3859

Published: 21/03/2019 Updated: 25/07/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 572
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

An out of bounds read flaw exists in libssh2 prior to 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libssh2 libssh2

fedoraproject fedora 28

fedoraproject fedora 29

debian debian linux 8.0

debian debian linux 9.0

netapp ontap select deploy administration utility -

opensuse leap 15.0

opensuse leap 42.3

Vendor Advisories

An issue has been found in libssh2 before 181 where a server could send a specially crafted partial packet in response to various commands such as: sha1 and sha226 key exchange, user auth list, user auth password response, public key auth response, channel startup/open/forward/ setenv/request pty/x11 and session start up The result would be a me ...
Debian Bug report logs - #924965 libssh2: CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 Package: src:libssh2; Maintainer for src:libssh2 is Mikhail Gusarov <dottedmag@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: ...
Chris Coulson discovered several vulnerabilities in libssh2, a SSH2 client-side library, which could result in denial of service, information leaks or the execution of arbitrary code For the stable distribution (stretch), these problems have been fixed in version 170-1+deb9u1 We recommend that you upgrade your libssh2 packages For the detailed ...
Arch Linux Security Advisory ASA-201903-13 ========================================== Severity: Critical Date : 2019-03-20 CVE-ID : CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862 CVE-2019-3863 Package : libssh2 Type : multiple issues Remote : Yes Link : ...
Summary libssh2 is a client-side C library implementing the SSH2 protocol  It supports regular terminal, SCP and SFTP sessions; port forwarding, X11 forwarding; password, key-based and keyboard-interactive authentication Libssh2 releases security update for nine vulenrabilities on March 18, 2019 CVE-2019-3855: Possible integer overflow in ...
Multiple integer overflow and out of bounds read/write vulnerabilities in the SSL VPN web-mode SSH client may allow an unauthenticated attacker to cause the SSL VPN user session to break (Denial of service) and possibly to run arbitrary code via specially crafted packets sent from a malicious SSH server This concerns the following CVEs on a preca ...
AT&T has released versions 1801-z for the Vyatta 5600 Details of these releases can be found at cloudibmcom/docs/infrastructure/virtual-router-appliance?topic=virtual-router-appliance-at-t-vyatta-5600-vrouter-software-patches#at-t-vyatta-5600-vrouter-software-patches ...

Mailing Lists

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] libssh2 (SSA:2019-077-01) New libssh2 packages are available for Slackware 142 and -current to fix security issues Here are the details from the Slackware 142 ChangeLog: +--------------------------+ patches/packages/libssh2-181-i586-1_slack142txz: Upgraded Fixed seve ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4431-1 security () debian org wwwdebianorg/security/ Salvatore Bonaccorso April 13, 2019 wwwdebianorg/security/faq ...
Hello! CVE-2019-3855 Possible integer overflow in transport read allows out-of-bounds write URL: wwwlibssh2org/CVE-2019-3855html Patch: libssh2org/180-CVE/CVE-2019-3855patch CVE-2019-3856 Possible integer overflow in keyboard interactive handling allows out-of-bounds write URL: wwwlibssh2org/CVE-2019-385 ...

Github Repositories

A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI for Web

TrivyWeb A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI for Web TrivyWeb use python django framework TOC Installation RHEL/CentOS Debian/Ubuntu Mac OS X / Homebrew Binary (Including Windows) From source Examples Scan an image Scan an image file Save the results as JSON Filter the vulnerabilities by severities Filter the vulnerabilities b

A Simple and Comprehensive Vulnerability Scanner for Containers and other Artifacts, Suitable for CI Table of Contents Abstract Features Installation RHEL/CentOS Debian/Ubuntu Arch Linux Homebrew Install Script Binary From source Quick Start Image Basic Docker Filesystem Embed in Dockerfile Git Repository Examples Standalone Scan an image Scan an image file Scan

A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI Table of Contents Abstract Features Installation RHEL/CentOS Debian/Ubuntu Arch Linux Mac OS X / Homebrew Binary From source Quick Start Basic Docker Examples Standalone Scan an image Scan an image file Scan an OCI image Save the results as JSON Save the results using a template Filter

A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI

A Simple and Comprehensive Vulnerability Scanner for Containers and other Artifacts, Suitable for CI Table of Contents Abstract Features Installation RHEL/CentOS Debian/Ubuntu Arch Linux Homebrew Install Script Binary From source Quick Start Image Basic Docker Filesystem Embed in Dockerfile Git Repository Examples Standalone Scan an image Scan an image file Scan

A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI

A Simple and Comprehensive Vulnerability Scanner for Containers and other Artifacts, Suitable for CI Table of Contents Abstract Features Installation RHEL/CentOS Debian/Ubuntu Arch Linux Homebrew Install Script Binary From source Quick Start Image Basic Docker Filesystem Embed in Dockerfile Git Repository Examples Standalone Scan an image Scan an image file Scan

References

CWE-125http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00102.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00103.htmlhttp://packetstormsecurity.com/files/152136/Slackware-Security-Advisory-libssh2-Updates.htmlhttp://www.openwall.com/lists/oss-security/2019/03/18/3http://www.securityfocus.com/bid/107485https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3859https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00006.htmlhttps://lists.debian.org/debian-lts-announce/2019/07/msg00024.htmlhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5DK6VO2CEUTAJFYIKWNZKEKYMYR3NO2O/https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XCWEA5ZCLKRDUK62QVVYMFWLWKOPX3LO/https://seclists.org/bugtraq/2019/Apr/25https://seclists.org/bugtraq/2019/Mar/25https://security.netapp.com/advisory/ntap-20190327-0005/https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-767https://www.debian.org/security/2019/dsa-4431https://www.libssh2.org/CVE-2019-3859.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2019-3862https://nvd.nist.govhttps://github.com/KorayAgaya/TrivyWeb