CVE-2019-3861: Critical severity oracle libssh2 vulnerability
A server could send a specially crafted SSH packet with a padding length value greater than the packet length. This would result in a buffer read out of bounds when decompressing the packet or result in a corrupted packet value.
Other sources
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-3861.
What software is affected by CVE-2019-3861?
The software affected by CVE-2019-3861 includes libssh2 before version 1.8.1, Debian Linux 8.0, NetApp ONTAP Select Deploy administration utility, and openSUSE Leap 15.0 and 42.3.
What is the severity of CVE-2019-3861?
The severity of CVE-2019-3861 is critical with a CVSS score of 9.1.