[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253390

 
 

909

 
 

197257

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Python Modules - (bulletinapr2018)

ID: oval:org.secpod.oval:def:2101930Date: (C)2019-12-31   (M)2022-10-10
Class: PATCHFamily: unix




transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

Platform:
Sun Solaris 11
Product:
library/python/paramiko
library/python/paramiko-34
library/python/paramiko-27
Reference:
bulletinapr2018
CVE-2018-7750
CVE    1
CVE-2018-7750
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies