CVE-2020-22218: High severity libssh2 libssh2 vulnerability
An issue was discovered in function libssh2packetadd in libssh2 1.10.0 allows attackers to access out of bounds memory.
Other sources
libssh2 is vulnerable to a denial of service, caused by an out-of-bounds read in the libssh2packetadd function. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-22218?
CVE-2020-22218 is a vulnerability in libssh2 1.10.0 that allows attackers to access out-of-bounds memory.
How severe is CVE-2020-22218?
CVE-2020-22218 has a severity rating of 7.5 (high).
What software versions are affected by CVE-2020-22218?
CVE-2020-22218 affects libssh2 1.10.0, ubuntu/libssh2 1.4.3-2ubuntu0.2+, ubuntu/libssh2 1.5.0-2ubuntu0.1+, ubuntu/libssh2 1.8.0-1ubuntu0.1, ubuntu/libssh2 1.8.0-2.1ubuntu0.1, and debian/libssh2 1.8.0-2.1+deb10u1, 1.10.0-3, and 1.11.0-2.
How can I fix CVE-2020-22218?
To fix CVE-2020-22218, update to a version of libssh2 that is not affected by the vulnerability.
Where can I find more information about CVE-2020-22218?
You can find more information about CVE-2020-22218 at the following references: [GitHub](https://github.com/libssh2/libssh2/pull/476), [Debian LTS](https://lists.debian.org/debian-lts-announce/2023/09/msg00006.html), [CVE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-22218).