TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2019-3856

HIGH
8.8

Beschreibung

An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.

CVE Details

CVSS v3.1 Bewertung8.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht3/25/2019
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

debian:debian_linuxfedoraproject:fedoralibssh2:libssh2netapp:ontap_select_deploy_administration_utilityopensuse:leaporacle:peoplesoft_enterprise_peopletoolsredhat:enterprise_linuxredhat:enterprise_linux_desktopredhat:enterprise_linux_serverredhat:enterprise_linux_server_ausredhat:enterprise_linux_server_eusredhat:enterprise_linux_server_tusredhat:enterprise_linux_workstation

Schwachen (CWE)

CWE-190CWE-787CWE-190CWE-787

Referenzen

https://access.redhat.com/errata/RHSA-2019:0679(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:1175(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:1652(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:1791(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:1943(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:2399(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3856(af854a3a-2127-422b-91ae-364da2661108)
https://seclists.org/bugtraq/2019/Apr/25(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20190327-0005/(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2019/dsa-4431(af854a3a-2127-422b-91ae-364da2661108)
https://www.libssh2.org/CVE-2019-3856.html(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.