CVE-2019-3860
Last modified
CVE-2019-3860 is a vulnerability of currently unknown severity. An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.. EPSS estimates a 5.12% chance of exploitation in the next 30 days.
Description
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libssh2 | Libssh2 | >= 0.3, <= 1.8.0 |
| Debian | Debian Linux | 8.0 |
| Netapp | Ontap Select Deploy Administration Utility | All versions |
| Opensuse | Leap | 15.0 |
| Opensuse | Leap | 42.3 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3860Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190327-0005/Third Party Advisory
- https://www.libssh2.org/CVE-2019-3860.htmlPatch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3860Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190327-0005/Third Party Advisory
- https://www.libssh2.org/CVE-2019-3860.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3860?
How severe is CVE-2019-3860?
How do I fix CVE-2019-3860?
Are you affected by CVE-2019-3860?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
