Description
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
References (18)
Scores
CVSS v3
7.3
EPSS
0.0656
EPSS Percentile
91.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-125
CWE-130
Status
published
Products (5)
debian/debian_linux
8.0
fedoraproject/fedora
29
libssh2/libssh2
< 1.8.1
netapp/ontap_select_deploy_administration_utility
opensuse/leap
42.3
Published
Mar 21, 2019
Tracked Since
Feb 18, 2026