CVE-2023-3603
Last modified
CVE-2023-3603 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A missing allocation check in sftp server processing read requests may cause a NULL dereference on low-memory conditions. The malicious client can request up to 4GB SFTP reads, causing allocation of up to 4GB buffers, which was not being checked for failure. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
A missing allocation check in sftp server processing read requests may cause a NULL dereference on low-memory conditions. The malicious client can request up to 4GB SFTP reads, causing allocation of up to 4GB buffers, which was not being checked for failure. This will likely crash the authenticated user's sftp server connection (if implemented as forking as recommended). For thread-based servers, this might also cause DoS for legitimate users. Given this code is not in any released versions, no security releases have been issued.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libssh | Libssh | < 0.8.9 |
References
- https://access.redhat.com/security/cve/CVE-2023-3603Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2221791Issue Tracking, Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-3603Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2221791Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3603?
How severe is CVE-2023-3603?
How do I fix CVE-2023-3603?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-36024Microsoft Edge (Chromium-based) Elevation of Privilege Vulne…7.1
- CVE-2023-36025Windows SmartScreen Security Feature Bypass Vulnerability8.8
- CVE-2023-36026Microsoft Edge (Chromium-based) Spoofing Vulnerability4.3
- CVE-2023-36027Microsoft Edge (Chromium-based) Elevation of Privilege Vulne…6.3
- CVE-2023-36028Microsoft Protected Extensible Authentication Protocol (PEAP…9.8
- CVE-2023-36029Microsoft Edge (Chromium-based) Spoofing Vulnerability4.3
- CVE-2023-36030Microsoft Dynamics 365 Sales Spoofing Vulnerability6.1
- CVE-2023-36031Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vu…5.4
- CVE-2023-36033Windows DWM Core Library Elevation of Privilege Vulnerabilit…7.8
- CVE-2023-36034Microsoft Edge (Chromium-based) Remote Code Execution Vulner…7.3
- CVE-2023-36035Microsoft Exchange Server Spoofing Vulnerability8
- CVE-2023-36036Windows Cloud Files Mini Filter Driver Elevation of Privileg…7.8
Are you affected by CVE-2023-3603?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
