[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2023-1756 --- libssh2

ID: oval:org.secpod.oval:def:1601723Date: (C)2023-06-13   (M)2023-11-10
Class: PATCHFamily: unix




An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory

Platform:
Amazon Linux AMI
Product:
libssh2
Reference:
ALAS-2023-1756
CVE-2019-3859
CVE-2019-3860
CVE    2
CVE-2019-3859
CVE-2019-3860

© SecPod Technologies