TROYANOSYVIRUS
Volver a CVEs

CVE-2019-3860

N/A

Descripcion

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

Detalles CVE

Puntuacion CVSS v3.1N/A
Publicado3/25/2019
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0

Productos afectados

debian:debian_linuxlibssh2:libssh2netapp:ontap_select_deploy_administration_utilityopensuse:leap

Debilidades (CWE)

CWE-125CWE-125

Referencias

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3860(af854a3a-2127-422b-91ae-364da2661108)
https://seclists.org/bugtraq/2019/Apr/25(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20190327-0005/(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2019/dsa-4431(af854a3a-2127-422b-91ae-364da2661108)
https://www.libssh2.org/CVE-2019-3860.html(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.