CVE-2019-16905
Summary
| CVE | CVE-2019-16905 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-09 20:15:00 UTC |
| Updated | 2023-03-01 01:56:00 UTC |
| Description | OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| SSD Advisory - OpenSSH Pre-Auth XMSS Integer Overflow - SSD Secure Disclosure |
MISC |
ssd-disclosure.com |
|
| Bug 1153537 – VUL-1: CVE-2019-16905: openssh: when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key |
MISC |
bugzilla.suse.com |
Issue Tracking, Third Party Advisory |
| src/usr.bin/ssh/sshkey-xmss.c - diff - 1.6 |
MISC |
cvsweb.openbsd.org |
Patch |
| 0day.life/exploits/0day-1009.html |
MISC |
0day.life |
Exploit, Third Party Advisory |
| oss-security - Announce: OpenSSH 8.1 released |
CONFIRM |
www.openwall.com |
Mailing List, Third Party Advisory |
| CVE-2019-16905 OpenSSH Pre-Auth Integer Overflow Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVS log for src/usr.bin/ssh/sshkey-xmss.c |
MISC |
cvsweb.openbsd.org |
Vendor Advisory |
| cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| OpenSSH: Release Notes |
CONFIRM |
www.openssh.com |
Release Notes |
| OpenSSH: Integer overflow (GLSA 201911-01) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591280 Siemens SCALANCE X-200RNA Switch Devices Denial of Service (DoS) Multiple Vulnerabilities (ICSA-22-349-21, SSA-412672)
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 710122 Gentoo Linux OpenSSH Integer overflow Vulnerability (GLSA 201911-01)
- 900092 CBL-Mariner Linux Security Update for openssh 8.0p1
- 902866 Common Base Linux Mariner (CBL-Mariner) Security Update for openssh (2523)