QID 355524
Date Published: 2023-07-03
QID 355524: Amazon Linux Security Advisory for libssh2 : AL2012-2023-423
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2019-3860:
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
CVE-2019-3859:
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
CVEs related to QID 355524
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2023-423 | Amazon Linux Bare Metal |
|