[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-7750 -- paramiko

ID: oval:org.secpod.oval:def:2001366Date: (C)2019-04-22   (M)2023-12-20
Class: VULNERABILITYFamily: unix




transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

Platform:
Debian 8.x
Debian 9.x
Product:
python-paramiko
Reference:
CVE-2018-7750
CVE    1
CVE-2018-7750
CPE    4
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:python_software_foundation:python-paramiko
cpe:/o:debian:debian_linux:8.0
...

© SecPod Technologies