CVE-2019-3859: Critical severity libssh2 libssh2 vulnerability
Published Mar 20, 2019
·Updated
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the libssh2packetrequire and libssh2packetrequirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
Affected Software
9 affected componentsFixes available
debian/libssh2
1.8.0-2.11.8.0-2.1+deb10u11.9.0-21.10.0-31.11.0-2
libssh2 libssh2<1.8.1
Fedoraproject Fedora=28
Fedoraproject Fedora=29
Debian Debian Linux=8.0
Debian Debian Linux=9.0
NetApp ONTAP Select Deploy administration utility
openSUSE Leap=15.0
openSUSE Leap=42.3
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 20, 2019
CVE Published
via MITRE·09:18 PM
Data Sourced
via MITRE·09:18 PM
DescriptionSeverityWeakness
Mar 21, 2019
Data Sourced
via NVD·04:01 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-3859?
CVE-2019-3859 is a vulnerability found in libssh2 before version 1.8.1.
2
What is the severity of CVE-2019-3859?
The severity of CVE-2019-3859 is critical with a CVSS score of 9.1.
3
How does CVE-2019-3859 affect libssh2?
CVE-2019-3859 can cause an out of bounds read on the _libssh2_packet_require and _libssh2_packet_requirev functions in libssh2.
4
What is the impact of CVE-2019-3859?
An attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
5
How can CVE-2019-3859 be fixed?
To fix CVE-2019-3859, users should upgrade to libssh2 version 1.8.1 or later.