Vulnerability CVE-2018-10933: Information
Description
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
Severity: CRITICAL (9.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
libssh | sisyphus | 0.8.4-alt2 | 0.10.6-alt1 | ALT-PU-2018-2504-1 | 215142 | Fixed |
libssh | p10 | 0.8.4-alt2 | 0.10.6-alt1 | ALT-PU-2018-2504-1 | 215142 | Fixed |
libssh | p9 | 0.8.4-alt2 | 0.9.6-alt1 | ALT-PU-2018-2504-1 | 215142 | Fixed |
libssh | p8 | 0.7.6-alt2 | 0.8.8-alt1 | ALT-PU-2018-2507-1 | 215125 | Fixed |
libssh | c10f1 | 0.8.4-alt2 | 0.10.6-alt1 | ALT-PU-2018-2504-1 | 215142 | Fixed |
libssh | c9f2 | 0.8.4-alt2 | 0.10.6-alt1 | ALT-PU-2018-2504-1 | 215142 | Fixed |
libssh | c7 | 0.7.6-alt2 | 0.7.6-alt2 | ALT-PU-2018-2552-1 | 215444 | Fixed |
mysql-workbench-community | sisyphus | 8.0.15-alt1 | 8.0.33-alt2.2 | ALT-PU-2019-1298-1 | 222682 | Fixed |
mysql-workbench-community | p10 | 8.0.15-alt1 | 8.0.25-alt2 | ALT-PU-2019-1298-1 | 222682 | Fixed |
mysql-workbench-community | p9 | 8.0.15-alt1 | 8.0.25-alt2 | ALT-PU-2019-1298-1 | 222682 | Fixed |
mysql-workbench-community | c10f1 | 8.0.15-alt1 | 8.0.25-alt2 | ALT-PU-2019-1298-1 | 222682 | Fixed |
mysql-workbench-community | c9f2 | 8.0.15-alt1 | 8.0.25-alt3 | ALT-PU-2019-1298-1 | 222682 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://www.libssh.org/security/advisories/CVE-2018-10933.txt |
|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10933 |
|
DSA-4322 |
|
USN-3795-1 |
|
[debian-lts-announce] 20181018 [SECURITY] [DLA 1548-1] libssh security update |
|
45638 |
|
105677 |
|
USN-3795-2 |
|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0016 |
|
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html |
|
https://security.netapp.com/advisory/ntap-20190118-0002/ |
|