#VU18253 Out-of-bounds read in libssh2 - CVE-2019-3862
Published: April 15, 2019 / Updated: October 26, 2020
libssh2
libssh2.org
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information or perform denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker can trick the victim to connect to a malicious SSH server, trigger out of bounds read and gain access to sensitive information or perform denial of service attack.