SB2019031915 - Out-of-bounds write in libssh2 (Alpine package)
Published: March 19, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2019-3863)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing total length of multiple keyboard interactive response messages that exceeds the value of unsigned char max characters. A remote attacker can trick the victim to connect to a malicious SSH server, trigger our of bounds write and execute arbitrary code on the system with privileges of the user, running the affected application.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=d60ef1f3b3cd3b40d41722b7de616227c0b83a2b
- https://git.alpinelinux.org/aports/commit/?id=eec223036af35046c74baca7b09d6a81aaccbe86
- https://git.alpinelinux.org/aports/commit/?id=0c38351d5beace23bc498ea5fc79b3ba6a012b6e
- https://git.alpinelinux.org/aports/commit/?id=27f813a2ece1924d1c8f2e02239ad214611599fb
- https://git.alpinelinux.org/aports/commit/?id=4f69ccce51fcfa18af42948e79d26c5d0ba42733