A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lwssshparseplaintext of the file plugins/protocollwssshbase/sshd.c of the component SSH Protocol Handler. Executing a manipulation of the argument msg_len can lead to resource consumption. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498. A patch should be applied to remediate this issue.
{
"binaries": [
{
"binary_version": "4.3.5-1",
"binary_name": "libwebsockets-evlib-ev"
},
{
"binary_version": "4.3.5-1",
"binary_name": "libwebsockets-evlib-glib"
},
{
"binary_version": "4.3.5-1",
"binary_name": "libwebsockets-evlib-uv"
},
{
"binary_version": "4.3.5-1",
"binary_name": "libwebsockets-test-server"
},
{
"binary_version": "4.3.5-1",
"binary_name": "libwebsockets-test-server-common"
},
{
"binary_version": "4.3.5-1",
"binary_name": "libwebsockets19t64"
}
]
}{
"binaries": [
{
"binary_version": "4.3.5-3ubuntu1",
"binary_name": "libwebsockets-evlib-ev"
},
{
"binary_version": "4.3.5-3ubuntu1",
"binary_name": "libwebsockets-evlib-glib"
},
{
"binary_version": "4.3.5-3ubuntu1",
"binary_name": "libwebsockets-evlib-uv"
},
{
"binary_version": "4.3.5-3ubuntu1",
"binary_name": "libwebsockets-test-server"
},
{
"binary_version": "4.3.5-3ubuntu1",
"binary_name": "libwebsockets-test-server-common"
},
{
"binary_version": "4.3.5-3ubuntu1",
"binary_name": "libwebsockets19t64"
}
]
}{
"binaries": [
{
"binary_version": "3.2.1-3ubuntu0.1~esm1",
"binary_name": "libwebsockets-test-server"
},
{
"binary_version": "3.2.1-3ubuntu0.1~esm1",
"binary_name": "libwebsockets-test-server-common"
},
{
"binary_version": "3.2.1-3ubuntu0.1~esm1",
"binary_name": "libwebsockets15"
}
]
}{
"binaries": [
{
"binary_version": "4.3.3-1.1ubuntu0.1~esm1",
"binary_name": "libwebsockets-evlib-ev"
},
{
"binary_version": "4.3.3-1.1ubuntu0.1~esm1",
"binary_name": "libwebsockets-evlib-glib"
},
{
"binary_version": "4.3.3-1.1ubuntu0.1~esm1",
"binary_name": "libwebsockets-evlib-uv"
},
{
"binary_version": "4.3.3-1.1ubuntu0.1~esm1",
"binary_name": "libwebsockets-test-server"
},
{
"binary_version": "4.3.3-1.1ubuntu0.1~esm1",
"binary_name": "libwebsockets-test-server-common"
},
{
"binary_version": "4.3.3-1.1ubuntu0.1~esm1",
"binary_name": "libwebsockets19t64"
}
]
}