CVE-2019-3863: Integer Overflow
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used by the SSH client as an index to copy memory causing in an out of bounds memory write error.
Other sources
A flaw was found in libssh2 before 1.8.1. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used as an index to copy memory causing in an out of bounds memory write error.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-3863?
CVE-2019-3863 is a vulnerability found in libssh2 before version 1.8.1.
How severe is CVE-2019-3863?
CVE-2019-3863 has a severity rating of 8.8 (high).
How can I fix CVE-2019-3863?
To fix CVE-2019-3863, update libssh2 to version 1.8.1 or later.
Which software is affected by CVE-2019-3863?
The software affected by CVE-2019-3863 includes libssh2, Debian Linux, NetApp ONTAP Select Deploy administration utility, openSUSE Leap, and Redhat Enterprise Linux.
Where can I find more information about CVE-2019-3863?
More information about CVE-2019-3863 can be found at the following links: [Link 1](https://github.com/libssh2/libssh2/commit/dc109a7f518757741590bb993c0c8412928ccec2), [Link 2](https://www.openwall.com/lists/oss-security/2019/03/18/3), [Link 3](https://libssh2.org/1.8.0-CVE/CVE-2019-3863.txt)