peter bassill · operator
$ cve CVE-2019-3859 JSON

CVE-2019-3859

9.1
CRITICAL · CVSS 3.1 · EPSS 6.3% (pctl 93)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS6.28% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-125
On CISA KEVno
Public exploitnone known
Published2019-03-21
Last modified2026-06-17

Affected (5)

VendorProduct
debiandebian linux
fedoraprojectfedora
libssh2libssh2
netappontap select deploy administration utility
opensuseleap

References

→ the Explorer  ·  watch your stack  ·  NVD