The vendor explicitly identifies these products as affected by this CVE.
- libssh2 as a component of Red Hat Enterprise Linux 6
- libssh2-devel as a component of Red Hat Enterprise Linux 6
- libssh2-docs as a component of Red Hat Enterprise Linux 6
- libssh2.src as a component of Red Hat Enterprise Linux 6
- rhtpa/rhtpa-trustification-service-rhel9 as a component of Red Hat Trusted Profile Analyzer
- Summary
- A flaw was found in the libssh2 library. A remote attacker can exploit an integer overflow vulnerability in the `userauth_password` function by manipulating the `username_len` or `password_len` arguments and cause a heap-based buffer overflow. This leads to a crash to the application linked to the library and potentially allows arbitrary code execution.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
