Buffer overflow in libssh - CVE-2021-3634

 

Buffer overflow in libssh - CVE-2021-3634

Published: August 31, 2021


Vulnerability identifier: #VU56217
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3634
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when handling shared secrets. A remote attacker can supply a shared secret of a different size, trigger a memory corruption during the second key re-exchange and crash the application or potentially execute arbitrary code.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

libssh
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openEuler
Ubuntu
Fedora
libssh (Debian package)
libssh (Red Hat package)
libssh-4 (Ubuntu package)
libssh
libssh-devel
libssh-debugsource
libssh-debuginfo
libssh-help
libssh-config
libssh4-32bit
libssh4-debuginfo
libssh4
libssh4-debuginfo-32bit
libssh4-32bit-debuginfo
net-libs/libssh
OpenShift API for Data Protection (OADP)
Secondary Scheduler Operator for Red Hat OpenShift (OSSO)
Red Hat OpenShift Serverless
OpenShift Service Mesh
OpenShift Virtualization
IBM Supplied MQ Advanced Queue Manager Container images
App Connect Enterprise Certified Container
Cryostat
Red Hat Advanced Cluster Management for Kubernetes
Ansible Automation Platform
Red Hat Advanced Cluster Security for Kubernetes
IBM MQ
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
Red Hat OpenStack
IBM Robotic Process Automation
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
OpenShift Developer Tools and Services
MySQL Workbench
PowerStore X
PowerStore T
IBM Cloud Pak for Watson AIOps
Storage Resource Manager
EMC Cloud Tiering Appliance
Dell EMC Storage Monitoring and Reporting (SMR)
RSA Authentication Manager

How to mitigate CVE-2021-3634

Install updates from vendor's website.

libssh - update to 0.9.6
libssh (Debian package) - update to 0.9.5-1+deb11u1
libssh (Red Hat package) - update to 0.9.6-3.el8
OpenShift API for Data Protection (OADP) - addressed in versions 1.0.4, 1.1.0
Secondary Scheduler Operator for Red Hat OpenShift (OSSO) - update to 1.0.1
Red Hat OpenShift Serverless - update to 1.22.1
App Connect Enterprise Certified Container - addressed in versions 1.1.10, 4.2.0
Migration Toolkit for Containers - addressed in versions 1.6.5, 1.7.2, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Cryostat - update to 2.1.1
OpenShift Service Mesh - update to 2.1.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.11, 2.4.5, 2.5.0
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.68.2, 3.69.2, 3.70
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 7, 7.5.0 Update Pack 3
MySQL Workbench - update to 8.0.28
libssh-4 (Ubuntu package) - addressed in versions 0.9.3-2ubuntu2.2, 0.9.5-1ubuntu0.1
libssh - update to 0.9.4-5
libssh-devel - update to 0.9.4-5
libssh-debugsource - update to 0.9.4-5
libssh-debuginfo - update to 0.9.4-5
libssh-help - update to 0.9.4-5
libssh - addressed in versions 0.9.6-1.fc33, 0.9.6-1.fc34, 0.9.6-1.fc35
libssh - update to 0.9.6-3
libssh-config - update to 0.9.6-3
libssh-devel - update to 0.9.6-3
libssh4-32bit - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh-devel - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh4-debuginfo - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh4 - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh-debugsource - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh-config - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh4-debuginfo-32bit - update to 0.9.8-3.12.2
libssh4-32bit-debuginfo - update to 0.9.8-150200.13.3.1
net-libs/libssh - update to 0.10.5
IBM MQ - addressed in versions 1.3.4 EUS, 1.8.2 CD
Netcool Operations Insight - update to 1.6.6
PowerStore X - update to 3.2.1.4-2386214
PowerStore T - update to 4.0.0.2-2365061
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.5.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
Storage Resource Manager - update to 4.10.0.3
OpenShift Virtualization - update to 4.11.0
Dell Secure Connect Gateway - update to 5.24.00.14
RSA Authentication Manager - update to 8.7 SP2 Patch 2
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.2.0.5-r2-eus, 9.2.5.0-r3
EMC Cloud Tiering Appliance - update to 13.2.0.2.29
Red Hat OpenStack - update to 16.2.z
IBM Robotic Process Automation - update to 21.0.3

External References

Related Security Bulletins