Integer overflow vulnerability in OpenSSH - CVE-2019-16905ID: oval:org.secpod.oval:def:92149 | Date: (C)2023-08-22 (M)2023-12-20 |
Class: VULNERABILITY | Family: unix |
OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm.
Platform: |
Debian 10.x |
Debian 11.x |
Debian 12.x |
Product: |
openssh-client |
openssh-server |