MGASA-2019-0139

Advisory lineage Upstream: 9 Downstream: 0
Published: 10 Apr 2019, 21:25
Last modified:16 Apr 2026, 04:26

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Apr 2019, 21:25
Published
Vulnerability first disclosed
16 Apr 2026, 04:26
Last Modified
Vulnerability information updated

Description

Updated libssh2 packages fix security vulnerability Possible integer overflow in transport read allows out-of-bounds write. (CVE-2019-3855) Possible integer overflow in keyboard interactive handling allows out-of-bounds write. (CVE-2019-3856) Possible integer overflow leading to zero-byte allocation and out-of-bounds write. (CVE-2019-3857) Possible zero-byte allocation leading to an out-of-bounds read. (CVE-2019-3858) Out-of-bounds reads with specially crafted payloads due to unchecked use of `_libssh2_packet_require` and `_libssh2_packet_requirev`. (CVE-2019-3859) Out-of-bounds reads with specially crafted SFTP packets. (CVE-2019-3860) Out-of-bounds reads with specially crafted SSH packets. (CVE-2019-3861) Out-of-bounds memory comparison. (CVE-2019-3862) Integer overflow in user authenicate keyboard interactive allows out-of-bounds writes. (CVE-2019-3863)

Affected Systems

  • mageialibssh2

    < 1.7.0-2.1.mga6

References (4)