MGASA-2019-0139
Dashboard / Vulnerabilities / MGASA-2019-0139
MGASA-2019-0139
Summary: Updated libssh2 packages fix security vulnerability
Details: Possible integer overflow in transport read allows out-of-bounds write. (CVE-2019-3855) Possible integer overflow in keyboard interactive handling allows out-of-bounds write. (CVE-2019-3856) Possible integer overflow leading to zero-byte allocation and out-of-bounds write. (CVE-2019-3857) Possible zero-byte allocation leading to an out-of-bounds read. (CVE-2019-3858) Out-of-bounds reads with specially crafted payloads due to unchecked use of `_libssh2_packet_require` and `_libssh2_packet_requirev`. (CVE-2019-3859) Out-of-bounds reads with specially crafted SFTP packets. (CVE-2019-3860) Out-of-bounds reads with specially crafted SSH packets. (CVE-2019-3861) Out-of-bounds memory comparison. (CVE-2019-3862) Integer overflow in user authenicate keyboard interactive allows out-of-bounds writes. (CVE-2019-3863)
References: https://advisories.mageia.org/MGASA-2019-0139.html, https://bugs.mageia.org/show_bug.cgi?id=24532, https://www.openwall.com/lists/oss-security/2019/03/18/3, http://lists.suse.com/pipermail/sle-security-updates/2019-March/005203.html
Affected packages
Package
Name: libssh2
Purl: pkg:rpm/mageia/libssh2?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
