CVE-2019-3863
Last modified
CVE-2019-3863 is a vulnerability of currently unknown severity. A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. EPSS estimates a 3.44% chance of exploitation in the next 30 days.
Description
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used by the SSH client as an index to copy memory causing in an out of bounds memory write error.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libssh2 | Libssh2 | < 1.8.1 |
| Debian | Debian Linux | 8.0 |
| Netapp | Ontap Select Deploy Administration Utility | All versions |
| Opensuse | Leap | 15.0 |
| Opensuse | Leap | 42.3 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 7.6 |
| Redhat | Enterprise Linux Server Eus | 7.6 |
| Redhat | Enterprise Linux Server Tus | 7.6 |
| Redhat | Enterprise Linux Workstation | 7.0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0679Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3863Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190327-0005/Third Party Advisory
- https://www.libssh2.org/CVE-2019-3863.htmlPatch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0679Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3863Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00032.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190327-0005/Third Party Advisory
- https://www.libssh2.org/CVE-2019-3863.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3863?
How severe is CVE-2019-3863?
How do I fix CVE-2019-3863?
Are you affected by CVE-2019-3863?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
