[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2023-2046 --- libssh2

ID: oval:org.secpod.oval:def:1701312Date: (C)2023-05-18   (M)2023-11-13
Class: PATCHFamily: unix




An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory

Platform:
Amazon Linux 2
Product:
libssh2
Reference:
ALAS2-2023-2046
CVE-2019-3859
CVE-2019-3860
CVE    2
CVE-2019-3859
CVE-2019-3860

© SecPod Technologies