[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2018-989 ---- python-paramiko, python26-paramiko, python27-paramiko

ID: oval:org.secpod.oval:def:1600865Date: (C)2018-04-06   (M)2022-04-18
Class: PATCHFamily: unix




Authentication bypass in transport.pytransport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step

Platform:
Amazon Linux AMI
Product:
python-paramiko
python26-paramiko
python27-paramiko
Reference:
ALAS-2018-989
CVE-2018-7750
CVE    1
CVE-2018-7750
CPE    2
cpe:/o:amazon:linux
cpe:/a:python_software_foundation:python-paramiko

© SecPod Technologies