PT-2023-25414 · Openssh+1 · Openssh+1
Zack Miele
·
Published
2023-07-21
·
Updated
2025-09-24
·
CVE-2023-3603
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
OpenSSH SFTP server (affected versions not specified)
Description
A missing allocation check in the SFTP server when processing read requests can cause a NULL dereference under low-memory conditions. A malicious client can request up to 4GB SFTP reads, leading to the allocation of large buffers without checking for failure. This can likely crash the authenticated user's SFTP server connection, especially in forking-based implementations, and may also cause a Denial of Service (DoS) for legitimate users in thread-based servers.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssh
Red Os