Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-7750

Опубликовано: 13 мар. 2018
Источник: ubuntu
Приоритет: high
CVSS2: 7.5
CVSS3: 9.8

Описание

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

РелизСтатусПримечание
artful

released

2.0.0-1ubuntu0.1
devel

released

2.0.0-1ubuntu1
esm-infra-legacy/trusty

released

1.10.1-1git1ubuntu0.1
esm-infra/xenial

released

1.16.0-1ubuntu0.1
precise/esm

not-affected

1.7.7.1-2ubuntu1.1
trusty

released

1.10.1-1git1ubuntu0.1
trusty/esm

released

1.10.1-1git1ubuntu0.1
upstream

needs-triage

xenial

released

1.16.0-1ubuntu0.1

Показывать по

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
почти 8 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

CVSS3: 9.8
nvd
почти 8 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

CVSS3: 9.8
debian
почти 8 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17. ...

suse-cvrf
почти 8 лет назад

Security update for python-paramiko

suse-cvrf
больше 7 лет назад

Security update for python-paramiko

7.5 High

CVSS2

9.8 Critical

CVSS3