PT-2023-25414 · Openssh+1 · Openssh+1

Zack Miele

·

Publicado

2023-07-21

·

Atualizado

2025-09-24

·

CVE-2023-3603

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSH SFTP server (affected versions not specified)
Description A missing allocation check in the SFTP server when processing read requests can cause a NULL dereference under low-memory conditions. A malicious client can request up to 4GB SFTP reads, leading to the allocation of large buffers without checking for failure. This can likely crash the authenticated user's SFTP server connection, especially in forking-based implementations, and may also cause a Denial of Service (DoS) for legitimate users in thread-based servers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-12375
CVE-2023-3603

Produtos afetados

Openssh
Red Os