CVE-2019-3859 is an out-of-bounds read vulnerability in libssh2 versions prior to 1.8.1, specifically within the _libssh2_packet_require and _libssh2_packet_requirev functions. This flaw affects various products including Debian, Fedora, NetApp, and OpenSUSE. It carries a critical CVSS score of 9.1, indicating a high impact with potential for remote attackers to cause Denial of Service or read sensitive client memory without requiring authentication or user interaction. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered significant community discussion with 11 mentions and some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.1CPE matchmatch criteria | cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:* | ||
28CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.