CVE-2019-3858: libssh2: Zero-byte allocation with a specially crafted SFTP packed leading to an out-of-bounds read

Severity: Critical

CVSS Score: 9.1

An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.