Page 2 of 11 results (0.005 seconds)
CVSS: 7.8EPSS: 0%CPEs: 8EXPL: 2

CVE-2019-16905 – Gentoo Linux Security Advisory 201911-01
https://notcve.org/view.php?id=CVE-2019-16905
09 Oct 2019 — OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH. OpenSSH 7.7 a 7.9 y 8.x anterior de la v... • https://0day.life/exploits/0day-1009.html • CWE-190: Integer Overflow or Wraparound •