Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-10933

Опубликовано: 17 окт. 2018
Источник: ubuntu
Приоритет: medium
EPSS Высокий
CVSS2: 6.4
CVSS3: 9.1

Описание

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

РелизСтатусПримечание
bionic

released

0.8.0~20170825.94fa1e38-1ubuntu0.1
cosmic

released

0.8.1-1ubuntu0.1
devel

released

0.8.1-1ubuntu0.1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [0.6.1-0ubuntu3.4]]
esm-infra/bionic

not-affected

0.8.0~20170825.94fa1e38-1ubuntu0.1
esm-infra/xenial

not-affected

0.6.3-4.3ubuntu0.1
precise/esm

DNE

trusty

released

0.6.1-0ubuntu3.4
trusty/esm

DNE

trusty was released [0.6.1-0ubuntu3.4]
upstream

needs-triage

Показывать по

EPSS

Процентиль: 99%
0.79379
Высокий

6.4 Medium

CVSS2

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
redhat
почти 7 лет назад

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

CVSS3: 9.1
nvd
почти 7 лет назад

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

CVSS3: 9.1
debian
почти 7 лет назад

A vulnerability was found in libssh's server-side state machine before ...

suse-cvrf
почти 7 лет назад

Security update for libssh

suse-cvrf
почти 7 лет назад

Security update for libssh

EPSS

Процентиль: 99%
0.79379
Высокий

6.4 Medium

CVSS2

9.1 Critical

CVSS3