Vulnerability CVE-2018-10933: Information

Description

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

Severity: CRITICAL (9.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Published: Oct. 17, 2018
Modified: Oct. 10, 2019
Error type identifier: CWE-287

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://www.libssh.org/security/advisories/CVE-2018-10933.txt
  • Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10933
  • Issue Tracking
  • Third Party Advisory
DSA-4322
  • Third Party Advisory
USN-3795-1
  • Third Party Advisory
[debian-lts-announce] 20181018 [SECURITY] [DLA 1548-1] libssh security update
  • Mailing List
  • Third Party Advisory
45638
  • Exploit
  • Third Party Advisory
  • VDB Entry
105677
  • Third Party Advisory
  • VDB Entry
USN-3795-2
  • Third Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0016
  • Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
  • Patch
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20190118-0002/
  • Third Party Advisory
    1. Configuration 1

      cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
      Start including
      0.8.0
      End excliding
      0.8.4

      cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
      Start including
      0.6.0
      End excliding
      0.7.6

      Configuration 2

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

      Configuration 5

      cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*

      cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:*

      cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:windows:*:*
      Start including
      7.3

      cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*

      cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:vsphere:*:*
      Start including
      9.4

      Configuration 6

      cpe:2.3:a:oracle:mysql_workbench:*:*:*:*:*:*:*:*
      End including
      8.0.13