PT-2019-6253 · Libssh2+6 · Libssh2+6

Kevin Backhouse

·

Published

2019-07-01

·

Updated

2025-10-27

·

CVE-2019-17498

CVSS v2.0

8.8

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions libssh2 versions 1.9.0 and earlier
Description The issue is related to an integer overflow in the SSH MSG DISCONNECT logic in packet.c, which enables an attacker to specify an arbitrary offset for a subsequent memory read. This could allow a crafted SSH server to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server.
Recommendations For libssh2 versions 1.9.0 and earlier, consider disabling the packet.c component until a patch is available to prevent potential exploitation. Restrict access to the SSH server to minimize the risk of sensitive information disclosure or denial of service. As a temporary workaround, avoid using the vulnerable packet.c logic in the SSH MSG DISCONNECT handling until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024_1130
ALSA-2024_1150
ALSA-2025_16880
ALT-PU-2020-2918
ALT-PU-2020-2949
ALT-PU-2021-2150
ALT-PU-2021-3271
ALT-PU-2024-1563
ALT-PU-2024-1973
AZL-6650
BDU:2022-05961
CESA-2020_3915
CVE-2019-17498
DLA-1991-1
DLA-2848-1
DLA-3559-1
ELSA-2020-3915
JLSEC-2025-188
MGASA-2019-0343
OPENSUSE-SU-2019:2483-1
OPENSUSE-SU-2019_2483-1
OPENSUSE-SU-2020:2126-1
OPENSUSE-SU-2020:2129-1
OPENSUSE-SU-2020_2126-1
OPENSUSE-SU-2020_2129-1
OPENSUSE-SU-2024:10999-1
RHSA-2020:3915
RHSA-2020_3915
SUSE-RU-2023:4066-1
SUSE-RU-2023:4192-1
SUSE-SU-2019:14206-1
SUSE-SU-2019:14226-1
SUSE-SU-2019:2900-1
SUSE-SU-2019:2900-2
SUSE-SU-2019:2936-1
SUSE-SU-2019_14206-1
SUSE-SU-2019_2900-1
SUSE-SU-2019_2900-2
SUSE-SU-2019_2936-1
SUSE-SU-2020:3551-1
SUSE-SU-2020_3551-1
USN-5308-1

Affected Products

Alt Linux
Astra Linux
Centos
Red Hat
Suse
Ubuntu
Libssh2