Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-7750

Опубликовано: 13 мар. 2018
Источник: ubuntu
Приоритет: high
EPSS Средний
CVSS2: 7.5
CVSS3: 9.8

Описание

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

РелизСтатусПримечание
artful

released

2.0.0-1ubuntu0.1
devel

released

2.0.0-1ubuntu1
esm-infra-legacy/trusty

released

1.10.1-1git1ubuntu0.1
esm-infra/xenial

released

1.16.0-1ubuntu0.1
precise/esm

not-affected

1.7.7.1-2ubuntu1.1
trusty

released

1.10.1-1git1ubuntu0.1
trusty/esm

released

1.10.1-1git1ubuntu0.1
upstream

needs-triage

xenial

released

1.16.0-1ubuntu0.1

Показывать по

EPSS

Процентиль: 94%
0.16054
Средний

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
больше 7 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

CVSS3: 9.8
nvd
больше 7 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

CVSS3: 9.8
debian
больше 7 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17. ...

suse-cvrf
больше 7 лет назад

Security update for python-paramiko

suse-cvrf
около 7 лет назад

Security update for python-paramiko

EPSS

Процентиль: 94%
0.16054
Средний

7.5 High

CVSS2

9.8 Critical

CVSS3