Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-7750

Опубликовано: 13 мар. 2018
Источник: debian
EPSS Средний

Описание

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
paramikofixed2.4.2-0.1package
paramikono-dsawheezypackage

Примечания

  • https://github.com/paramiko/paramiko/issues/1175

  • https://github.com/paramiko/paramiko/commit/fa29bd8446c8eab237f5187d28787727b4610516

EPSS

Процентиль: 94%
0.16054
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

CVSS3: 9.8
redhat
больше 7 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

CVSS3: 9.8
nvd
больше 7 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

suse-cvrf
больше 7 лет назад

Security update for python-paramiko

suse-cvrf
около 7 лет назад

Security update for python-paramiko

EPSS

Процентиль: 94%
0.16054
Средний