PT-2018-3975 · Npm · Sshpk

Chalker

·

Published

2018-02-25

·

Updated

2023-01-30

·

CVE-2018-3737

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions sshpk versions prior to 1.13.2 sshpk versions prior to 1.14.1
Description The issue is related to the parsing of crafted invalid public keys, which can lead to a regular expression denial of service. This can cause a denial of service, allowing a remote attacker to disrupt service. The estimated number of potentially affected devices is not specified.
Recommendations For versions prior to 1.13.2, update to version 1.13.2 or later. For versions prior to 1.14.1, update to version 1.14.1 or later.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2024-01219
CVE-2018-3737
GHSA-2M39-62FM-Q8R3
RHSA-2020:2625

Affected Products

Sshpk