Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-7749

Опубликовано: 12 мар. 2018
Источник: debian

Описание

The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-asyncsshfixed1.12.1-1package

Примечания

  • https://github.com/ronf/asyncssh/commit/16e6ebfa893167c7d9d3f6dc7a2c0d197e47f43a

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.

CVSS3: 9.8
nvd
почти 8 лет назад

The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.

CVSS3: 9.8
github
больше 3 лет назад

AsyncSSH SSH Server Authentication Bypass