Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 30: FEDORA-2019-70a9d4f970 Moderate: libssh2 Memory Overflow

fedora
Calendar Grey April 4, 2019
Dist Fedora Esm H88
Fedora 30 upgrade addresses the libssh2 buffer overflows that could lead to memory corruption during connections to non-secure servers.
This update addresses various overflow conditions that could result in possible memory read/write out of bounds errors or zero byte allocations when connected to a malicious server...

Summary

libssh2 is a library implementing the SSH2 protocol as defined by

Internet Drafts: SECSH-TRANS(22), SECSH-USERAUTH(25),

SECSH-CONNECTION(23), SECSH-ARCH(20), SECSH-FILEXFER(06)*,

SECSH-DHGEX(04), and SECSH-NUMBERS(10).

This update addresses various overflow conditions that could result in possible

memory read/write out of bounds errors or zero byte allocations when connected

to a malicious server.

[ 1 ] Bug #1687313 - CVE-2019-3863 libssh2: Integer overflow in user authenticate keyboard interactive allows out-of-bounds writes

https://bugzilla.redhat.com/show_bug.cgi?id=1687313

[ 2 ] Bug #1687312 - CVE-2019-3862 libssh2: Out-of-bounds memory comparison with specially crafted message channel request

https://bugzilla.redhat.com/show_bug.cgi?id=1687312

[ 3 ] Bug #1687311 - CVE-2019-3861 libssh2: Out-of-bounds reads with specially crafted SSH packets

https://bugzilla.redhat.com/show_bug.cgi?id=1687311

[ 4 ] Bug #1687310 - CVE-2019-3860 libssh2: Out-of-bounds reads with specially crafted SFTP packets

https://bugzilla.redhat.com/show_bug.cgi?id=1687310

[ 5 ] Bug #1687307 - CVE-2019-3859 libssh2: Unchecked use of _libssh2_packet_require and _libssh2_packet_requirev resulting in out-of-bounds read

https://bugzilla.redhat.com/show_bug.cgi?id=1687307

[ 6 ] Bug #1687306 - CVE-2019-3858 libssh2: Zero-byte allocation with a specially crafted SFTP packed leading to an out-of-bounds read

https://bugzilla.redhat.com/show_bug.cgi?id=1687306

[ 7 ] Bug #1687305 - CVE-2019-3857 libssh2: Integer overflow in SSH packet processing channel resulting in out of bounds write

https://bugzilla.redhat.com/show_bug.cgi?id=1687305

[ 8 ] Bug #1687304 - CVE-2019-3856 libssh2: Integer overflow in keyboard interactive handling resulting in out of bounds write

https://bugzilla.redhat.com/show_bug.cgi?id=1687304

[ 9 ] Bug #1687303 - CVE-2019-3855 libssh2: Integer overflow in transport read resulting in out of bounds write

https://bugzilla.redhat.com/show_bug.cgi?id=1687303

su -c 'dnf upgrade --advisory FEDORA-2019-70a9d4f970' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 30
Version: 1.8.2
Release: 1.fc30
Summary: A library implementing the SSH2 protocol

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here