Back

HIGH

libssh2: Integer overflow in transport read resulting in out of bounds write

Published Mar 21, 2019

Description

An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.

Affected products

Remediation

Red Hat statement

This flaw was present in libssh2 packages included in Red Hat Virtualization Hypervisor and Management Appliance, however libssh2 in these hosts is never exposed to malicious clients or servers.

References (32)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Mar 21, 2019
Updated Dec 17, 2025
Reserved Jan 3, 2019

CISA Vulnrichment

Updated Dec 17, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Mar 13, 2019
Bugzilla 1687303

ENISA EUVD

Assigner redhat
Published Mar 21, 2019
Updated Dec 17, 2025

GitHub

No data