CVE-2019-3863
Summary
| CVE | CVE-2019-3863 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-25 18:29:00 UTC |
| Updated | 2023-11-07 03:10:00 UTC |
| Description | A flaw was found in libssh2 before 1.8.1. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used as an index to copy memory causing in an out of bounds memory write error. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| [SECURITY] Fedora 28 Update: libssh2-1.8.1-1.fc28 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Bugtraq: [SECURITY] [DSA 4431-1] libssh2 security update |
BUGTRAQ |
seclists.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| March 2019 Libssh2 Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-4431-1 libssh2 |
DEBIAN |
www.debian.org |
|
| libssh2 Security Advisory: CVE-2019-3863 |
MISC |
www.libssh2.org |
Patch, Vendor Advisory |
| [SECURITY] Fedora 28 Update: libssh2-1.8.1-1.fc28 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [security-announce] openSUSE-SU-2019:1075-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| [SECURITY] [DLA 1730-1] libssh2 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Oracle Critical Patch Update - October 2019 |
MISC |
www.oracle.com |
|
| [security-announce] openSUSE-SU-2019:1109-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| 1687313 – (CVE-2019-3863) CVE-2019-3863 libssh2: Integer overflow in user authenticate keyboard interactive allows out-of-bounds writes |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377077 Alibaba Cloud Linux Security Update for libssh2 (ALINUX2-SA-2019:0018)
- 378237 Virtuozzo Linux Security Update for libssh2-docs (VZLSA-2019:1652)
- 500318 Alpine Linux Security Update for libssh2
- 504085 Alpine Linux Security Update for libssh2
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 750528 OpenSUSE Security Update for libssh2_org (openSUSE-SU-2020:2129-1)
- 750530 OpenSUSE Security Update for libssh2_org (openSUSE-SU-2020:2126-1)