Bug 1687312 (CVE-2019-3862)
Summary: | CVE-2019-3862 libssh2: Out-of-bounds memory comparison with specially crafted message channel request | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Andrej Nemec <anemec> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | bmcclain, dblechte, dfediuck, djuran, eedri, erik-fedora, kdudka, mgoldboi, michal.skrivanek, mike, paul, rjones, rschiron, sbonazzo, security-response-team, sherold, yturgema |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | libssh2 1.8.1 | Doc Type: | If docs needed, set a value |
Doc Text: |
An out of bounds read flaw was discovered in libssh2 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a denial of service or read data in the client memory.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2019-07-29 19:18:31 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1688494, 1688495, 1688496, 1690247, 1690248, 1690408, 1696058, 1697698, 1714210 | ||
Bug Blocks: | 1687317 |
Description
Andrej Nemec
2019-03-11 09:00:00 UTC
Acknowledgments: Name: the libssh2 project Upstream: Chris Coulson (Canonical Ltd.) Reference: https://www.openwall.com/lists/oss-security/2019/03/18/3 Upstream Patch: https://libssh2.org/1.8.0-CVE/CVE-2019-3862.patch External References: https://www.libssh2.org/CVE-2019-3862.html Created libssh tracking bugs for this issue: Affects: fedora-all [bug 1690246] Created mingw-libssh2 tracking bugs for this issue: Affects: fedora-all [bug 1690247] Created mingw-libssh2 tracking bugs for this issue: Affects: epel-7 [bug 1690248] Created libssh2 tracking bugs for this issue: Affects: fedora-all [bug 1690408] This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:1884 https://access.redhat.com/errata/RHSA-2019:1884 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2019-3862 Statement: This flaw was present in libssh2 packages included in Red Hat Virtualization Hypervisor and Management Appliance, however libssh2 in these hosts is never exposed to malicious clients or servers. libssh2 is no longer included in the virt module since Red Hat Enterprise Linux 8.1. |