TROYANOSYVIRUS
Volver a CVEs

CVE-2019-3856

HIGH
8.8

Descripcion

An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.

Detalles CVE

Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado3/25/2019
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0

Productos afectados

debian:debian_linuxfedoraproject:fedoralibssh2:libssh2netapp:ontap_select_deploy_administration_utilityopensuse:leaporacle:peoplesoft_enterprise_peopletoolsredhat:enterprise_linuxredhat:enterprise_linux_desktopredhat:enterprise_linux_serverredhat:enterprise_linux_server_ausredhat:enterprise_linux_server_eusredhat:enterprise_linux_server_tusredhat:enterprise_linux_workstation

Debilidades (CWE)

CWE-190CWE-787CWE-190CWE-787

Referencias

https://access.redhat.com/errata/RHSA-2019:0679(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:1175(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:1652(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:1791(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:1943(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:2399(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3856(af854a3a-2127-422b-91ae-364da2661108)
https://seclists.org/bugtraq/2019/Apr/25(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20190327-0005/(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2019/dsa-4431(af854a3a-2127-422b-91ae-364da2661108)
https://www.libssh2.org/CVE-2019-3856.html(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.