USN-5308-1
Dashboard / Vulnerabilities / USN-5308-1
USN-5308-1
Summary: libssh2 vulnerabilities
Details: It was discovered that libssh2 mishandled certain input. If libssh2 were used to connect to a malicious or compromised SSH server, a remote, unauthenticated attacker could possibly execute arbitrary code on the client system. (CVE-2019-3855) It was discovered that libssh2 incorrectly handled prompt requests. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2019-3856) It was discovered that libssh2 incorrectly handled SSH_MSG_CHANNEL_REQUEST packets. A remote attacker could possibly use this issue to execute arbitrary code, cause a denial of service, or obtain sensitive information. (CVE-2019-3857, CVE-2019-3862) It was discovered that libssh2 incorrectly handled specially crafted SFTP packets. A remote attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2019-3858) It was discovered that libssh2 incorrectly handled certain specially crafted packets. A remote attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2019-3859) It was discovered that libssh2 incorrectly handled SFTP packets with empty payloads. A remote attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2019-3860) It was discovered that libssh2 incorrectly handled padding values in SSH packets. A remote attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2019-3861) It was discovered that libssh2 incorrectly handled interactive response messages length. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2019-3863) It was discovered that libssh2 incorrectly handled the Diffie Hellman key exchange. A remote attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2019-13115) It was discovered that libssh2 incorrectly handled bound checks in SSH_MSG_DISCONNECT. A remote attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2019-17498)
References: https://ubuntu.com/security/notices/USN-5308-1, https://ubuntu.com/security/CVE-2019-3855, https://ubuntu.com/security/CVE-2019-3856, https://ubuntu.com/security/CVE-2019-3857, https://ubuntu.com/security/CVE-2019-3858, https://ubuntu.com/security/CVE-2019-3859, https://ubuntu.com/security/CVE-2019-3860, https://ubuntu.com/security/CVE-2019-3861, https://ubuntu.com/security/CVE-2019-3862, https://ubuntu.com/security/CVE-2019-3863, https://ubuntu.com/security/CVE-2019-13115, https://ubuntu.com/security/CVE-2019-17498
Affected packages
Package
Name: libssh2
Purl: pkg:deb/ubuntu/libssh2?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
