CVE-2019-3863
Last modified
CVE-2019-3863 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. EPSS estimates a 3.44% chance of exploitation in the next 30 days.
Description
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used by the SSH client as an index to copy memory causing in an out of bounds memory write error.
Metrics
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libssh2 | Libssh2 | < 1.8.1 |
| Debian | Debian Linux | 8.0 |
| Netapp | Ontap Select Deploy Administration Utility | All versions |
| Opensuse | Leap | 15.0 |
| Opensuse | Leap | 42.3 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.6 |
| Redhat | Enterprise Linux Server Eus | 7.6 |
| Redhat | Enterprise Linux Server Tus | 7.6 |
| Redhat | Enterprise Linux Workstation | 7.0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0679Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3863Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190327-0005/Third Party Advisory
- https://www.libssh2.org/CVE-2019-3863.htmlPatch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0679Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3863Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190327-0005/Third Party Advisory
- https://www.libssh2.org/CVE-2019-3863.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3863?
How severe is CVE-2019-3863?
How do I fix CVE-2019-3863?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-3857An integer overflow flaw which could lead to an out of bound…8.8
- CVE-2019-3858An out of bounds read flaw was discovered in libssh2 before …5
- CVE-2019-3859An out of bounds read flaw was discovered in libssh2 before …9.1
- CVE-2019-3860An out of bounds read flaw was discovered in libssh2 before …5
- CVE-2019-3861An out of bounds read flaw was discovered in libssh2 before …5
- CVE-2019-3862An out of bounds read flaw was discovered in libssh2 before …7.3
- CVE-2019-3864A vulnerability was discovered in all quay-2 versions before…8.8
- CVE-2019-3865A vulnerability was found in quay-2, where a stored XSS vuln…6.1
- CVE-2019-3866An information-exposure vulnerability was discovered where o…5.5
- CVE-2019-3867A vulnerability was found in the Quay web application. Sessi…4.1
- CVE-2019-3868Keycloak up to version 6.0.0 allows the end user token (acce…3.8
- CVE-2019-3869When running Tower before 3.4.3 on OpenShift or Kubernetes, …7.2
Are you affected by CVE-2019-3863?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
