Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Mageia: 2019-0043 Critical: libssh Authentication Bypass Issue

mageia
Calendar Grey January 20, 2019
Dist Mageia Esm H88
MGASA-2019-0043 - Updated libssh packages fix security vulnerability Publication date: 20 Jan 2019 U
libssh versions 0.6 and above have an authentication bypass vulnerability in the server code

Summary

libssh versions 0.6 and above have an authentication bypass vulnerability in the server code. By presenting the server an SSH2_MSG_USERAUTH_SUCCESS message in place of the SSH2_MSG_USERAUTH_REQUEST message which the server would expect to initiate authentication, the attacker could successfully authentciate without any credentials (CVE-2018-10933).

References

- https://bugs.mageia.org/show_bug.cgi?id=23711

- https://www.libssh.org/security/advisories/CVE-2018-10933.txt

- - - https://www.cve.org/CVERecord?id=CVE-2018-10933

Resolution

SRPMS

- 6/core/libssh-0.7.7-1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 20 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0043.html
Type: security
CVE: CVE-2018-10933

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here