[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-7750 -- paramiko

ID: oval:org.secpod.oval:def:2001366Date: (C)2019-04-22   (M)2023-12-20
Class: VULNERABILITYFamily: unix




transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

Platform:
Debian 8.x
Debian 9.x
Product:
python-paramiko
Reference:
CVE-2018-7750
CVE    1
CVE-2018-7750
CPE    4
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:python_software_foundation:python-paramiko
cpe:/o:debian:debian_linux:8.0
...

© SecPod Technologies