CVE-2019-3856

HIGH

libssh2 < 1.8.1 - Remote Code Execution via Keyboard Prompt Request Parsing

Title source: llm
STIX 2.1

Description

An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.

References (16)

Core 16
Core References
Patch, Vendor Advisory x_refsource_misc
https://www.libssh2.org/CVE-2019-3856.html
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3856
Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/03/msg00032.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190327-0005/
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0679
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.html
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.html
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2019/dsa-4431
Mailing List, Third Party Advisory mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Apr/25
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1175
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1652
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1791
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1943
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:2399

Scores

CVSS v3 8.8
EPSS 0.0439
EPSS Percentile 89.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-190 CWE-787
Status published
Products (16)
debian/debian_linux 8.0
debian/debian_linux 9.0
fedoraproject/fedora 28
libssh2/libssh2 < 1.8.1
netapp/ontap_select_deploy_administration_utility
opensuse/leap 15.0
opensuse/leap 42.3
oracle/peoplesoft_enterprise_peopletools 8.56
oracle/peoplesoft_enterprise_peopletools 8.57
redhat/enterprise_linux 8.0
... and 6 more
Published Mar 25, 2019
Tracked Since Feb 18, 2026