CVE-2019-3859
9.1
CRITICAL · CVSS 3.1 · EPSS 6.3% (pctl 93)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
| EPSS | 6.28% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-125 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-03-21 |
| Last modified | 2026-06-17 |
Affected (5)
| Vendor | Product |
|---|---|
| debian | debian linux |
| fedoraproject | fedora |
| libssh2 | libssh2 |
| netapp | ontap select deploy administration utility |
| opensuse | leap |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00040.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00102.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00103.html
- http://packetstormsecurity.com/files/152136/Slackware-Security-Advisory-libssh2-Updates.html
- http://www.openwall.com/lists/oss-security/2019/03/18/3
- http://www.securityfocus.com/bid/107485
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3859
- https://lists.debian.org/debian-lts-announce/2019/03/msg00032.html
- https://lists.debian.org/debian-lts-announce/2019/04/msg00006.html
- https://lists.debian.org/debian-lts-announce/2019/07/msg00024.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5DK6VO2CEUTAJFYIKWNZKEKYMYR3NO2O/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCWEA5ZCLKRDUK62QVVYMFWLWKOPX3LO/
- https://seclists.org/bugtraq/2019/Apr/25
- https://seclists.org/bugtraq/2019/Mar/25
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-767
- https://www.debian.org/security/2019/dsa-4431
- https://www.libssh2.org/CVE-2019-3859.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
→ the Explorer · watch your stack · NVD