Candidate: CVE-2019-3857 PublicDate: 2019-03-25 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3857 https://www.libssh2.org/CVE-2019-3857.html https://github.com/libssh2/libssh2/pull/315 Description: An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server. Ubuntu-Description: It was discovered that libssh2 incorrectly handled SSH_MSG_CHANNEL_REQUEST packets. A remote attacker could possibly use this issue to execute arbitrary code. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_libssh2: upstream_libssh2: needs-triage precise/esm_libssh2: DNE trusty_libssh2: ignored (out of standard support) trusty/esm_libssh2: needed bionic_libssh2: needed xenial_libssh2: ignored (end of standard support, was needed) cosmic_libssh2: ignored (reached end-of-life) disco_libssh2: not-affected (1.8.0-2.1) eoan_libssh2: not-affected (1.8.0-2.1) focal_libssh2: not-affected (1.8.0-2.1) groovy_libssh2: not-affected (1.8.0-2.1) hirsute_libssh2: not-affected (1.8.0-2.1) impish_libssh2: not-affected (1.8.0-2.1) jammy_libssh2: not-affected (1.8.0-2.1) devel_libssh2: not-affected (1.8.0-2.1)