PT-2018-1662 · Libssh+3 · Libssh+3

Peter Winter-Smith

·

Published

2018-10-16

·

Updated

2025-08-01

·

CVE-2018-10933

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libssh versions prior to 0.7.6 libssh versions prior to 0.8.4
Description A vulnerability was found in libssh's server-side state machine. It allows a malicious client to create channels without first performing authentication, resulting in unauthorized access. The issue is related to errors in the authentication procedure, which can be exploited by a remote attacker using a specially crafted message to bypass authentication.
Recommendations For versions prior to 0.7.6, update to version 0.7.6 or later. For versions prior to 0.8.4, update to version 0.8.4 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2504
ALT-PU-2019-1298
BDU:2018-01221
CVE-2018-10933
DLA-1548-1
DSA-4322-1
LIBSSHAUTHBYPASS2018
MGASA-2019-0043
OPENSUSE-SU-2018_3200-1
OPENSUSE-SU-2018_3245-1
OPENSUSE-SU-2024:10998-1
SUSE-SU-2018:3162-1
SUSE-SU-2018:3253-1
SUSE-SU-2018_3162-1
SUSE-SU-2018_3253-1
USN-3795-1
USN-3795-2
USN-3795-3

Affected Products

Alt Linux
Suse
Ubuntu
Libssh