PT-2018-1662 · Libssh+3 · Libssh+3

Peter Winter-Smith

·

Publicado

2018-10-16

·

Atualizado

2025-08-01

·

CVE-2018-10933

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libssh versions prior to 0.7.6 libssh versions prior to 0.8.4
Description A vulnerability was found in libssh's server-side state machine. It allows a malicious client to create channels without first performing authentication, resulting in unauthorized access. The issue is related to errors in the authentication procedure, which can be exploited by a remote attacker using a specially crafted message to bypass authentication.
Recommendations For versions prior to 0.7.6, update to version 0.7.6 or later. For versions prior to 0.8.4, update to version 0.8.4 or later.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2504
ALT-PU-2019-1298
BDU:2018-01221
CVE-2018-10933
DLA-1548-1
DSA-4322-1
LIBSSHAUTHBYPASS2018
MGASA-2019-0043
OPENSUSE-SU-2018_3200-1
OPENSUSE-SU-2018_3245-1
OPENSUSE-SU-2024:10998-1
SUSE-SU-2018:3162-1
SUSE-SU-2018:3253-1
SUSE-SU-2018_3162-1
SUSE-SU-2018_3253-1
USN-3795-1
USN-3795-2
USN-3795-3

Produtos afetados

Alt Linux
Suse
Ubuntu
Libssh