libssh2是一款实现SSH2协议的客户端C库,它能够执行远程命令、文件传输,同时为远程的程序提供安全的传输通道。 libssh2中存在输入验证错误漏洞,该漏洞源于_libssh2_packet_add()函数没有正确地检查SSH_MSG_CHANNEL_REQUEST消息的namelen值。远程攻击者可利用该漏洞在客户端系统上执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The libssh2 Project | libssh2 | 1.8.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-3856 | libssh2 输入验证错误漏洞 | |
| CVE-2019-3860 | libssh2 缓冲区错误漏洞 | |
| CVE-2019-3861 | libssh2 缓冲区错误漏洞 | |
| CVE-2019-3863 | libssh2 缓冲区错误漏洞 |
No comments yet