Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia: 2019-0139 Moderate: Libssh2 Integer Overflow Issues

mageia
Calendar Grey April 10, 2019
Dist Mageia Esm H88
On April 10, 2019, updated libssh2 packages from Mageia resolved concerns regarding integer overflow vulnerabilities and out-of-bounds memory writes.
Possible integer overflow in transport read allows out-of-bounds write

Summary

Possible integer overflow in transport read allows out-of-bounds write. (CVE-2019-3855)
Possible integer overflow in keyboard interactive handling allows out-of-bounds write. (CVE-2019-3856)
Possible integer overflow leading to zero-byte allocation and out-of-bounds write. (CVE-2019-3857)
Possible zero-byte allocation leading to an out-of-bounds read. (CVE-2019-3858)
Out-of-bounds reads with specially crafted payloads due to unchecked use of `_libssh2_packet_require` and `_libssh2_packet_requirev`. (CVE-2019-3859)
Out-of-bounds reads with specially crafted SFTP packets. (CVE-2019-3860)
Out-of-bounds reads with specially crafted SSH packets. (CVE-2019-3861)
Out-of-bounds memory comparison. (CVE-2019-3862)
Integer overflow in user authenicate keyboard interactive allows out-of-bounds writes. (CVE-2019-3863)

References

- https://bugs.mageia.org/show_bug.cgi?id=24532

- https://www.openwall.com/lists/oss-security/2019/03/18/3

- http://lists.suse.com/pipermail/sle-security-updates/2019-March/005203.html

- https://www.cve.org/CVERecord?id=CVE-2019-3855

- https://www.cve.org/CVERecord?id=CVE-2019-3856

- https://www.cve.org/CVERecord?id=CVE-2019-3857

- https://www.cve.org/CVERecord?id=CVE-2019-3858

- https://www.cve.org/CVERecord?id=CVE-2019-3859

- https://www.cve.org/CVERecord?id=CVE-2019-3860

- https://www.cve.org/CVERecord?id=CVE-2019-3861

- https://www.cve.org/CVERecord?id=CVE-2019-3862

- https://www.cve.org/CVERecord?id=CVE-2019-3863

Resolution

SRPMS

- 6/core/libssh2-1.7.0-2.1.mga6

Publication date: 10 Apr 2019
URL: https://advisories.mageia.org/MGASA-2019-0139.html
Type: security
CVE: CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3858, CVE-2019-3859, CVE-2019-3860, CVE-2019-3861, CVE-2019-3862, CVE-2019-3863

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here