[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-7750 -- paramiko

ID: oval:org.secpod.oval:def:2001366Date: (C)2019-04-22   (M)2023-12-20
Class: VULNERABILITYFamily: unix




transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

Platform:
Debian 8.x
Debian 9.x
Product:
python-paramiko
Reference:
CVE-2018-7750
CVE    1
CVE-2018-7750
CPE    4
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:python_software_foundation:python-paramiko
cpe:/o:debian:debian_linux:8.0
...

© SecPod Technologies