Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.108729
Category:General
Title:OpenSSH 7.7 - 7.9, 8.x < 8.1 Integer Overflow Vulnerability
Summary:OpenSSH is prone to an integer overflow vulnerability.
Description:Summary:
OpenSSH is prone to an integer overflow vulnerability.

Vulnerability Insight:
An exploitable integer overflow bug was found in the private key
parsing code for the XMSS key type. This key type is still experimental and support for it is not
compiled by default. No user-facing autoconf option exists in portable OpenSSH to enable it.

Vulnerability Impact:
Successfully exploitation could lead to memory corruption and
local code execution.

Affected Software/OS:
OpenSSH versions 7.7 through 7.9 and 8.x before 8.1.

Solution:
Update to version 8.1 or later.

CVSS Score:
4.4

CVSS Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-16905
https://security.gentoo.org/glsa/201911-01
https://0day.life/exploits/0day-1009.html
https://bugzilla.suse.com/show_bug.cgi?id=1153537
https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshkey-xmss.c
https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshkey-xmss.c.diff?r1=1.5&r2=1.6&f=h
https://ssd-disclosure.com/archives/4033/ssd-advisory-openssh-pre-auth-xmss-integer-overflow
CopyrightCopyright (C) 2020 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.