openSUSE Security Update : libssh2_org (openSUSE-2019-1075)

high Nessus Plugin ID 123494
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Synopsis

The remote openSUSE host is missing a security update.

Description

This update for libssh2_org fixes the following issues :

Security issues fixed: 	

- CVE-2019-3861: Fixed Out-of-bounds reads with specially crafted SSH packets (bsc#1128490).

- CVE-2019-3862: Fixed Out-of-bounds memory comparison with specially crafted message channel request packet (bsc#1128492).

- CVE-2019-3860: Fixed Out-of-bounds reads with specially crafted SFTP packets (bsc#1128481).

- CVE-2019-3863: Fixed an Integer overflow in user authenticate keyboard interactive which could allow out-of-bounds writes with specially crafted keyboard responses (bsc#1128493).

- CVE-2019-3856: Fixed a potential Integer overflow in keyboard interactive handling which could allow out-of-bounds write with specially crafted payload (bsc#1128472).

- CVE-2019-3859: Fixed Out-of-bounds reads with specially crafted payloads due to unchecked use of
_libssh2_packet_require and _libssh2_packet_requirev (bsc#1128480).

- CVE-2019-3855: Fixed a potential Integer overflow in transport read which could allow out-of-bounds write with specially crafted payload (bsc#1128471).

- CVE-2019-3858: Fixed a potential zero-byte allocation which could lead to an out-of-bounds read with a specially crafted SFTP packet (bsc#1128476).

- CVE-2019-3857: Fixed a potential Integer overflow which could lead to zero-byte allocation and out-of-bounds with specially crafted message channel request SSH packet (bsc#1128474).

Other issue addressed :

- Libbssh2 will stop using keys unsupported types in the known_hosts file (bsc#1091236). This update was imported from the SUSE:SLE-12:Update update project.

Solution

Update the affected libssh2_org packages.

See Also

https://bugzilla.opensuse.org/show_bug.cgi?id=1091236

https://bugzilla.opensuse.org/show_bug.cgi?id=1128471

https://bugzilla.opensuse.org/show_bug.cgi?id=1128472

https://bugzilla.opensuse.org/show_bug.cgi?id=1128474

https://bugzilla.opensuse.org/show_bug.cgi?id=1128476

https://bugzilla.opensuse.org/show_bug.cgi?id=1128480

https://bugzilla.opensuse.org/show_bug.cgi?id=1128481

https://bugzilla.opensuse.org/show_bug.cgi?id=1128490

https://bugzilla.opensuse.org/show_bug.cgi?id=1128492

https://bugzilla.opensuse.org/show_bug.cgi?id=1128493

Plugin Details

Severity: High

ID: 123494

File Name: openSUSE-2019-1075.nasl

Version: 1.4

Type: local

Agent: unix

Published: 3/29/2019

Updated: 1/19/2021

Dependencies: ssh_get_info.nasl

Risk Information

CVSS Score Source: CVE-2019-3855

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: E:U/RL:OF/RC:C

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:libssh2-1, p-cpe:/a:novell:opensuse:libssh2-1-32bit, p-cpe:/a:novell:opensuse:libssh2-1-debuginfo, p-cpe:/a:novell:opensuse:libssh2-1-debuginfo-32bit, p-cpe:/a:novell:opensuse:libssh2-devel, p-cpe:/a:novell:opensuse:libssh2_org-debugsource, cpe:/o:novell:opensuse:42.3

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 3/28/2019

Vulnerability Publication Date: 3/21/2019

Reference Information

CVE: CVE-2019-3855, CVE-2019-3856, CVE-2019-3857, CVE-2019-3858, CVE-2019-3859, CVE-2019-3860, CVE-2019-3861, CVE-2019-3862, CVE-2019-3863