ZeroHour

CVE-2019-17498

PoC ×2
CVSS 3.1
8.1 high
EPSS
4%p89
Published
()
Modified
Description

In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server.

Vendors
libssh2fedoraprojectopensusedebiannetapp
Products
libssh2, fedora, leap, debian linux, active iq unified manager, element software, hci management node, ontap select deploy administration utility, solidfire, bootstrap os
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.