Blame SOURCES/0007-libssh2-1.8.0-CVE-2019-3861.patch

0b3366
From 77bc71f4ca2949a11110092034dd0705faa6d7b5 Mon Sep 17 00:00:00 2001
0b3366
From: Kamil Dudka <kdudka@redhat.com>
0b3366
Date: Tue, 19 Mar 2019 13:43:34 +0100
0b3366
Subject: [PATCH] Resolves: CVE-2019-3861 - fix out-of-bounds reads with
0b3366
 specially crafted SSH packets
0b3366
0b3366
Upstream-Patch: https://libssh2.org/1.8.0-CVE/CVE-2019-3861.patch
0b3366
---
0b3366
 src/transport.c | 3 +++
0b3366
 1 file changed, 3 insertions(+)
0b3366
0b3366
diff --git a/src/transport.c b/src/transport.c
0b3366
index 5349284..6224c4f 100644
0b3366
--- a/src/transport.c
0b3366
+++ b/src/transport.c
0b3366
@@ -442,6 +442,9 @@ int _libssh2_transport_read(LIBSSH2_SESSION * session)
0b3366
             }
0b3366
 
0b3366
             p->padding_length = block[4];
0b3366
+            if ( p->padding_length > p->packet_length - 1 ) {
0b3366
+                return LIBSSH2_ERROR_DECRYPT;
0b3366
+            }
0b3366
 
0b3366
             /* total_num is the number of bytes following the initial
0b3366
                (5 bytes) packet length and padding length fields */
0b3366
-- 
0b3366
2.17.2
0b3366