CVE-2019-3858
21.03.2019, 21:29
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libssh2 | libssh2 | 𝑥 < 1.8.1 |
| debian | debian_linux | 8.0 |
| netapp | ontap_select_deploy_administration_utility | - |
| opensuse | leap | 15.0 |
| opensuse | leap | 42.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libssh2 |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libssh2-1 |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libssh2-1-32bit |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| libssh2-devel |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References