Libssh2

Libssh2

25 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.32%
  • Veröffentlicht 24.07.2026 16:45:24
  • Zuletzt bearbeitet 30.07.2026 15:41:05

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller th...

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 24.07.2026 16:42:18
  • Zuletzt bearbeitet 30.07.2026 15:44:38

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsyste...

Medienbericht
  • EPSS 0.37%
  • Veröffentlicht 24.07.2026 16:35:28
  • Zuletzt bearbeitet 30.07.2026 15:44:47

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-G...

Medienbericht
  • EPSS 0.28%
  • Veröffentlicht 24.07.2026 16:32:39
  • Zuletzt bearbeitet 07.08.2026 01:07:10

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server ...

  • EPSS 0.44%
  • Veröffentlicht 28.06.2026 02:16:32
  • Zuletzt bearbeitet 30.06.2026 17:42:04

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized en...

  • EPSS 0.71%
  • Veröffentlicht 28.06.2026 02:16:32
  • Zuletzt bearbeitet 30.06.2026 20:27:36

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplic...

Medienbericht
  • EPSS 1.03%
  • Veröffentlicht 18.06.2026 20:18:29
  • Zuletzt bearbeitet 14.07.2026 23:17:19

libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause...

Medienbericht Exploit
  • EPSS 2.03%
  • Veröffentlicht 17.06.2026 19:03:15
  • Zuletzt bearbeitet 14.07.2026 22:17:17

libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large pac...

Medienbericht
  • EPSS 0.92%
  • Veröffentlicht 17.06.2026 18:44:18
  • Zuletzt bearbeitet 14.07.2026 22:17:17

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a craft...

  • EPSS 0.47%
  • Veröffentlicht 01.05.2026 21:30:11
  • Zuletzt bearbeitet 15.07.2026 01:17:01

A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such manipulation of the argument username_len/password_len leads to integer overflow. The attack m...