Vulnerability CVE-2018-10933: Information
Description
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
Severity: CRITICAL (9.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Fixed packages
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://www.libssh.org/security/advisories/CVE-2018-10933.txt |
|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10933 |
|
DSA-4322 |
|
USN-3795-1 |
|
[debian-lts-announce] 20181018 [SECURITY] [DLA 1548-1] libssh security update |
|
45638 |
|
105677 |
|
USN-3795-2 |
|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0016 |
|
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html |
|
https://security.netapp.com/advisory/ntap-20190118-0002/ |
|