VDB
JLSEC-2025-188
JLSEC-2025-188
PUBLISHED
CVSS 5.800000190734863 MEDIUM
In libssh2 v1.9.0 and earlier versions, the `SSH_MSG_DISCONNECT` logic in packet.c has an integer...
Risk Scores
CVSS 2.0
5.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Julia | LibSSH2_jll | 0 |
| Julia | LibSSH2_jll | 0, 0 |
Timeline
- Oct 27, 2025 CVE Published
- Jul 23, 2026 CVE Updated
References
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00026.html url
- http://packetstormsecurity.com/files/172835/libssh2-1.9.0-Out-Of-Bounds-Read.html url
- https://blog.semmle.com/libssh2-integer-overflow-CVE-2019-17498/ url
- https://github.com/kevinbackhouse/SecurityExploits/tree/8cbdbbe6363510f7d9ceec685373da12e6fc752d/libssh2/out_of_bounds_read_disconnect_CVE-2019-17498 url
- https://github.com/libssh2/libssh2/blob/42d37aa63129a1b2644bf6495198923534322d64/src/packet.c#L480 url
- https://github.com/libssh2/libssh2/commit/dedcbd106f8e52d5586b0205bc7677e4c9868f9c url
- https://lists.debian.org/debian-lts-announce/2019/11/msg00010.html url
- https://lists.debian.org/debian-lts-announce/2021/12/msg00013.html url
- https://lists.debian.org/debian-lts-announce/2023/09/msg00006.html url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22H4Q5XMGS3QNSA7OCL3U7UQZ4NXMR5O/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TY7EEE34RFKCTXTMBQQWWSLXZWSCXNDB/ url
- https://security.netapp.com/advisory/ntap-20220909-0004/ url