Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-4478

Опубликовано: 06 дек. 2010
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.

РелизСтатусПримечание
dapper

not-affected

code not present
devel

not-affected

1:5.7p1-1ubuntu1
hardy

not-affected

code not present
karmic

not-affected

code not present
lucid

not-affected

not enabled at compile time
maverick

not-affected

not enabled at compile time
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 90%
0.04242
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

redhat
почти 16 лет назад

OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.

CVSS3: 9.8
nvd
больше 15 лет назад

OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.

CVSS3: 9.8
debian
больше 15 лет назад

OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly val ...

CVSS3: 9.8
github
около 4 лет назад

OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.

fstec
около 12 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 90%
0.04242
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3