ALT-PU-2019-1729-1
Closed vulnerabilities
BDU:2019-01303
Уязвимость библиотеки libssh2, связанная с чтением за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании или раскрыть защищаемую информацию
BDU:2019-01304
Уязвимость библиотеки libssh2, вызванная целочисленным переполнением, позволяющая нарушителю выполнить произвольный код
BDU:2019-03331
Уязвимость функции _libssh2_transport_read (src/transport.c) библиотеки libssh2, позволяющая нарушителю выполнить произвольный код
BDU:2019-03795
Уязвимость бибиотеки libssh2, связанная с записью за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании, выполнить произвольный код или раскрыть защищаемую информацию
BDU:2019-03864
Уязвимость команды SSH_MSG_CHANNEL_REQUEST библиотеки libssh2, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к защищаемой информации
BDU:2019-03865
Уязвимость библиотеки libssh2, связанная с ошибками обработки несоответствия параметра длины, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к защищаемой информации
BDU:2019-03866
Уязвимость библиотеки libssh2, связанная с чтением данных за границами буфера, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к защищаемой информации
BDU:2019-03867
Уязвимость функций _libssh2_packet_require и _libssh2_packet_requirev библиотеки libssh2, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к защищаемой информации
BDU:2019-03871
Уязвимость библиотеки libssh2, связанная с чтением данных за границами буфера, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к защищаемой информации
BDU:2019-03897
Уязвимость библиотеки libssh2, связанная с целочисленным переполнением, позволяющая нарушителю выполнить произвольный код
BDU:2019-03898
Уязвимость библиотеки libssh2, связанная с целочисленным переполнением, позволяющая нарушителю выполнить произвольный код
BDU:2019-03917
Уязвимость команды SSH_MSG_CHANNEL_REQUEST библиотеки libssh2, позволяющая нарушителю выполнить произвольный код
BDU:2021-06331
Уязвимость функции userauth_keyboard_interactive() в компоненте userauth.c библиотеки libssh2, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2016-0787
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
- FEDORA-2016-215a2219b1
- FEDORA-2016-215a2219b1
- FEDORA-2016-7942ee2cc5
- FEDORA-2016-7942ee2cc5
- openSUSE-SU-2016:0639
- openSUSE-SU-2016:0639
- DSA-3487
- DSA-3487
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
- 82514
- 82514
- https://bto.bluecoat.com/security-advisory/sa120
- https://bto.bluecoat.com/security-advisory/sa120
- https://kc.mcafee.com/corporate/index?page=content&id=SB10156
- https://kc.mcafee.com/corporate/index?page=content&id=SB10156
- https://puppet.com/security/cve/CVE-2016-0787
- https://puppet.com/security/cve/CVE-2016-0787
- GLSA-201606-12
- GLSA-201606-12
- https://www.libssh2.org/adv_20160223.html
- https://www.libssh2.org/adv_20160223.html
- https://www.libssh2.org/CVE-2016-0787.patch
- https://www.libssh2.org/CVE-2016-0787.patch
Modified: 2024-11-21
CVE-2019-3855
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1109
- openSUSE-SU-2019:1109
- http://packetstormsecurity.com/files/152136/Slackware-Security-Advisory-libssh2-Updates.html
- http://packetstormsecurity.com/files/152136/Slackware-Security-Advisory-libssh2-Updates.html
- 20190927 APPLE-SA-2019-9-26-7 Xcode 11.0
- 20190927 APPLE-SA-2019-9-26-7 Xcode 11.0
- [oss-security] 20190318 [SECURITY ADVISORIES] libssh2
- [oss-security] 20190318 [SECURITY ADVISORIES] libssh2
- 107485
- 107485
- RHSA-2019:0679
- RHSA-2019:0679
- RHSA-2019:1175
- RHSA-2019:1175
- RHSA-2019:1652
- RHSA-2019:1652
- RHSA-2019:1791
- RHSA-2019:1791
- RHSA-2019:1943
- RHSA-2019:1943
- RHSA-2019:2399
- RHSA-2019:2399
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3855
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3855
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- FEDORA-2019-3348cb4934
- FEDORA-2019-3348cb4934
- FEDORA-2019-9d85600fc7
- FEDORA-2019-9d85600fc7
- FEDORA-2019-5885663621
- FEDORA-2019-5885663621
- FEDORA-2019-f31c14682f
- FEDORA-2019-f31c14682f
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190319 [slackware-security] libssh2 (SSA:2019-077-01)
- 20190319 [slackware-security] libssh2 (SSA:2019-077-01)
- 20190927 APPLE-SA-2019-9-26-7 Xcode 11.0
- 20190927 APPLE-SA-2019-9-26-7 Xcode 11.0
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://support.apple.com/kb/HT210609
- https://support.apple.com/kb/HT210609
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-767
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-767
- DSA-4431
- DSA-4431
- https://www.libssh2.org/CVE-2019-3855.html
- https://www.libssh2.org/CVE-2019-3855.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Modified: 2024-11-21
CVE-2019-3856
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1109
- openSUSE-SU-2019:1109
- RHSA-2019:0679
- RHSA-2019:0679
- RHSA-2019:1175
- RHSA-2019:1175
- RHSA-2019:1652
- RHSA-2019:1652
- RHSA-2019:1791
- RHSA-2019:1791
- RHSA-2019:1943
- RHSA-2019:1943
- RHSA-2019:2399
- RHSA-2019:2399
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3856
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3856
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- FEDORA-2019-3348cb4934
- FEDORA-2019-3348cb4934
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://security.netapp.com/advisory/ntap-20190327-0005/
- DSA-4431
- DSA-4431
- https://www.libssh2.org/CVE-2019-3856.html
- https://www.libssh2.org/CVE-2019-3856.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Modified: 2024-11-21
CVE-2019-3857
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1109
- openSUSE-SU-2019:1109
- RHSA-2019:0679
- RHSA-2019:0679
- RHSA-2019:1175
- RHSA-2019:1175
- RHSA-2019:1652
- RHSA-2019:1652
- RHSA-2019:1791
- RHSA-2019:1791
- RHSA-2019:1943
- RHSA-2019:1943
- RHSA-2019:2399
- RHSA-2019:2399
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3857
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3857
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- FEDORA-2019-3348cb4934
- FEDORA-2019-3348cb4934
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://security.netapp.com/advisory/ntap-20190327-0005/
- DSA-4431
- DSA-4431
- https://www.libssh2.org/CVE-2019-3857.html
- https://www.libssh2.org/CVE-2019-3857.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Modified: 2024-11-21
CVE-2019-3858
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1109
- openSUSE-SU-2019:1109
- http://packetstormsecurity.com/files/152136/Slackware-Security-Advisory-libssh2-Updates.html
- http://packetstormsecurity.com/files/152136/Slackware-Security-Advisory-libssh2-Updates.html
- [oss-security] 20190318 [SECURITY ADVISORIES] libssh2
- [oss-security] 20190318 [SECURITY ADVISORIES] libssh2
- 107485
- 107485
- RHSA-2019:2136
- RHSA-2019:2136
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3858
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3858
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- FEDORA-2019-3348cb4934
- FEDORA-2019-3348cb4934
- FEDORA-2019-f31c14682f
- FEDORA-2019-f31c14682f
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190319 [slackware-security] libssh2 (SSA:2019-077-01)
- 20190319 [slackware-security] libssh2 (SSA:2019-077-01)
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-767
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-767
- DSA-4431
- DSA-4431
- https://www.libssh2.org/CVE-2019-3858.html
- https://www.libssh2.org/CVE-2019-3858.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Modified: 2024-11-21
CVE-2019-3859
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1109
- openSUSE-SU-2019:1109
- openSUSE-SU-2019:1290
- openSUSE-SU-2019:1290
- openSUSE-SU-2019:1291
- openSUSE-SU-2019:1291
- http://packetstormsecurity.com/files/152136/Slackware-Security-Advisory-libssh2-Updates.html
- http://packetstormsecurity.com/files/152136/Slackware-Security-Advisory-libssh2-Updates.html
- [oss-security] 20190318 [SECURITY ADVISORIES] libssh2
- [oss-security] 20190318 [SECURITY ADVISORIES] libssh2
- 107485
- 107485
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3859
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3859
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- [debian-lts-announce] 20190402 [SECURITY] [DLA 1730-2] libssh2 regression update
- [debian-lts-announce] 20190402 [SECURITY] [DLA 1730-2] libssh2 regression update
- [debian-lts-announce] 20190725 [SECURITY] [DLA 1730-3] libssh2 regression update
- [debian-lts-announce] 20190725 [SECURITY] [DLA 1730-3] libssh2 regression update
- FEDORA-2019-3348cb4934
- FEDORA-2019-3348cb4934
- FEDORA-2019-f31c14682f
- FEDORA-2019-f31c14682f
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190319 [slackware-security] libssh2 (SSA:2019-077-01)
- 20190319 [slackware-security] libssh2 (SSA:2019-077-01)
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-767
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-767
- DSA-4431
- DSA-4431
- https://www.libssh2.org/CVE-2019-3859.html
- https://www.libssh2.org/CVE-2019-3859.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Modified: 2024-11-21
CVE-2019-3860
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1109
- openSUSE-SU-2019:1109
- openSUSE-SU-2019:1640
- openSUSE-SU-2019:1640
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3860
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3860
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- [debian-lts-announce] 20190730 [SECURITY] [DLA 1730-4] libssh2 regression update
- [debian-lts-announce] 20190730 [SECURITY] [DLA 1730-4] libssh2 regression update
- FEDORA-2019-3348cb4934
- FEDORA-2019-3348cb4934
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://security.netapp.com/advisory/ntap-20190327-0005/
- DSA-4431
- DSA-4431
- https://www.libssh2.org/CVE-2019-3860.html
- https://www.libssh2.org/CVE-2019-3860.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Modified: 2024-11-21
CVE-2019-3861
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1109
- openSUSE-SU-2019:1109
- RHSA-2019:2136
- RHSA-2019:2136
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3861
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3861
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- FEDORA-2019-3348cb4934
- FEDORA-2019-3348cb4934
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://security.netapp.com/advisory/ntap-20190327-0005/
- DSA-4431
- DSA-4431
- https://www.libssh2.org/CVE-2019-3861.html
- https://www.libssh2.org/CVE-2019-3861.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Modified: 2024-11-21
CVE-2019-3862
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1109
- openSUSE-SU-2019:1109
- http://packetstormsecurity.com/files/152136/Slackware-Security-Advisory-libssh2-Updates.html
- http://packetstormsecurity.com/files/152136/Slackware-Security-Advisory-libssh2-Updates.html
- [oss-security] 20190318 [SECURITY ADVISORIES] libssh2
- [oss-security] 20190318 [SECURITY ADVISORIES] libssh2
- 107485
- 107485
- RHSA-2019:1884
- RHSA-2019:1884
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3862
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3862
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- FEDORA-2019-3348cb4934
- FEDORA-2019-3348cb4934
- FEDORA-2019-f31c14682f
- FEDORA-2019-f31c14682f
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190319 [slackware-security] libssh2 (SSA:2019-077-01)
- 20190319 [slackware-security] libssh2 (SSA:2019-077-01)
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-767
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2019-767
- DSA-4431
- DSA-4431
- https://www.libssh2.org/CVE-2019-3862.html
- https://www.libssh2.org/CVE-2019-3862.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Modified: 2024-11-21
CVE-2019-3863
A flaw was found in libssh2 before 1.8.1. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used as an index to copy memory causing in an out of bounds memory write error.
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1075
- openSUSE-SU-2019:1109
- openSUSE-SU-2019:1109
- RHSA-2019:0679
- RHSA-2019:0679
- RHSA-2019:1175
- RHSA-2019:1175
- RHSA-2019:1652
- RHSA-2019:1652
- RHSA-2019:1791
- RHSA-2019:1791
- RHSA-2019:1943
- RHSA-2019:1943
- RHSA-2019:2399
- RHSA-2019:2399
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3863
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3863
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- [debian-lts-announce] 20190326 [SECURITY] [DLA 1730-1] libssh2 security update
- FEDORA-2019-3348cb4934
- FEDORA-2019-3348cb4934
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- 20190415 [SECURITY] [DSA 4431-1] libssh2 security update
- https://security.netapp.com/advisory/ntap-20190327-0005/
- https://security.netapp.com/advisory/ntap-20190327-0005/
- DSA-4431
- DSA-4431
- https://www.libssh2.org/CVE-2019-3863.html
- https://www.libssh2.org/CVE-2019-3863.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html