CVE-2019-3862: Critical severity libssh2 libssh2 vulnerability
A server could send a specially crafted SSHMSGCHANNELREQUEST packet with an exit status message and no payload. This would result in an out of bounds memory comparison.
Other sources
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSHMSGCHANNELREQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-3862?
CVE-2019-3862 is an out of bounds read flaw in libssh2 before version 1.8.1.
How does CVE-2019-3862 impact the system?
CVE-2019-3862 can be exploited by a remote attacker to cause a Denial of Service or read data in the client memory.
What is the severity of CVE-2019-3862?
The severity of CVE-2019-3862 is critical with a CVSS score of 9.1 out of 10.
Which software versions are affected by CVE-2019-3862?
Versions before 1.8.1 of libssh2, 1.8.0-2.1, 1.8.0-2.1+deb10u1, 1.9.0-2, 1.10.0-3, and 1.11.0-2 are affected.
How can I fix CVE-2019-3862?
To fix CVE-2019-3862, update libssh2 to version 1.8.1 or later.