F5-K000148713: Medium severity F5 BIG-IQ Centralized Management vulnerability
CVE-2019-3858 An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. CVE-2019-3862 An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSHMSGCHANNELREQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000148713?
The severity of F5-K000148713 is high due to the potential for Denial of Service and data exposure.
How do I fix F5-K000148713?
To fix F5-K000148713, upgrade your F5 BIG-IQ Centralized Management product to version 8.3.0 or higher.
What vulnerabilities are addressed in F5-K000148713?
F5-K000148713 addresses CVE-2019-3858 and CVE-2019-3862, which involve out of bounds read flaws.
Who is affected by F5-K000148713?
F5-K000148713 affects users of F5 BIG-IQ Centralized Management versions between 8.2.0 and 8.3.0.
What can an attacker do with F5-K000148713 vulnerability?
An attacker exploiting F5-K000148713 could potentially cause a Denial of Service or read sensitive client memory data.