Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13472
HistoryMar 19, 2019 - 3:01 a.m.

Denial Of Service (DoS)

2019-03-1903:01:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.003 Low

EPSS

Percentile

71.1%

libssh2.so is vulnerable to denial of service. A malicious server could send a SSH_MSG_CHANNEL_REQUEST packet with an exit signal message having a length of maximum unsigned integer value. This results in a length value of 1, which would cause a memory write out of bounds error or zero byte allocation when memory is allocated.

References