CVE-2019-3862

HIGH

Libssh2 < 1.8.1 - Denial of Service

Title source: rule
STIX 2.1

Description

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

References (18)

Scores

CVSS v3 7.3
EPSS 0.0656
EPSS Percentile 91.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-125 CWE-130
Status published
Products (5)
debian/debian_linux 8.0
fedoraproject/fedora 29
libssh2/libssh2 < 1.8.1
netapp/ontap_select_deploy_administration_utility
opensuse/leap 42.3
Published Mar 21, 2019
Tracked Since Feb 18, 2026