REDHAT-BUG-2464597: Integer Overflow
A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauthpassword of the file src/userauth.c. Such manipulation of the argument usernamelen/passwordlen leads to integer overflow. The attack may be launched remotely. The name of the patch is 256d04b60d80bf1190e96b0ad1e91b2174d744b1. A patch should be applied to remediate this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libssh2to a version that resolves this vulnerability.Fixed in 1.11.1Patch 256d04b60d80bf1190e96b0ad1e91b2174d744b1
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2464597?
The severity of REDHAT-BUG-2464597 is high with a score of 7.
What is the main vulnerability identified in REDHAT-BUG-2464597?
The main vulnerability in REDHAT-BUG-2464597 is an integer overflow in the userauth_password function of libssh2.
How can I fix REDHAT-BUG-2464597?
To fix REDHAT-BUG-2464597, apply the recommended patches provided by the maintainers of libssh2.
What versions of libssh2 are affected by REDHAT-BUG-2464597?
REDHAT-BUG-2464597 affects libssh2 versions up to 1.11.1.
Can REDHAT-BUG-2464597 be exploited remotely?
Yes, REDHAT-BUG-2464597 can be exploited remotely.