Bug 1687311 (CVE-2019-3861)
Summary: | CVE-2019-3861 libssh2: Out-of-bounds reads with specially crafted SSH packets | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Andrej Nemec <anemec> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | bmcclain, dblechte, dfediuck, djuran, eedri, erik-fedora, kdudka, mgoldboi, michal.skrivanek, mike, paul, rjones, rschiron, sbonazzo, security-response-team, sherold, yturgema |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | libssh2 1.8.1 | Doc Type: | If docs needed, set a value |
Doc Text: |
An out of bounds read flaw was discovered in libssh2 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able to cause a denial of service or read data in the client memory.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2019-08-06 13:22:11 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1688446, 1688447, 1688448, 1690247, 1690248, 1690408, 1696058, 1697699 | ||
Bug Blocks: | 1687317 |
Description
Andrej Nemec
2019-03-11 08:59:21 UTC
Acknowledgments: Name: the libssh2 project Upstream: Chris Coulson (Canonical Ltd.) Reference: https://www.openwall.com/lists/oss-security/2019/03/18/3 Upstream Patch: https://libssh2.org/1.8.0-CVE/CVE-2019-3861.patch External References: https://www.libssh2.org/CVE-2019-3861.html Created libssh tracking bugs for this issue: Affects: fedora-all [bug 1690246] Created mingw-libssh2 tracking bugs for this issue: Affects: fedora-all [bug 1690247] Created mingw-libssh2 tracking bugs for this issue: Affects: epel-7 [bug 1690248] Created libssh2 tracking bugs for this issue: Affects: fedora-all [bug 1690408] This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:2136 https://access.redhat.com/errata/RHSA-2019:2136 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-3861 Statement: This flaw was present in libssh2 packages included in Red Hat Virtualization Hypervisor and Management Appliance, however libssh2 in these hosts is never exposed to malicious clients or servers. libssh2 is no longer included in the virt module since Red Hat Enterprise Linux 8.1. |