Products from major vendors such as F5 and Red Hat are affected by a major vulnerability that came to light this week and which resides in the libssh library.. The vulnerability, which is tracked in infosec circles as CVE-2018-10933, is an authentication bypass in the libssh code that handles server-side login procedures. The link for this article located at ZDNet is no longer available. . A significant vulnerability in libssh allows for authentication circumvention, affecting numerous vendor solutions.. libssh Security, Authentication Bypass, Vendor Impact, Software Flaw, Security Alert. . LinuxSecurity.com Team
A four-year-old severe vulnerability has been discovered in the Secure Shell (SSH) implementation library known as Libssh that could allow anyone to completely bypass authentication and gain unfettered administrative control over a vulnerable server without requiring a password.. The security vulnerability, tracked as CVE-2018-10933, is an authentication-bypass issue that was introduced in Libssh version 0.6 released earlier 2014, leaving thousands of enterprise servers open to hackers for the last four years. The link for this article located at The Hacker News is no longer available. . A critical vulnerability in OpenSSH allows cybercriminals to gain full access to systems, circumventing all security measures.. LibSSH, Authentication Bypass, Remote Exploitation. . LinuxSecurity.com Team
The developers of the multi-platform LGPLv2.1-licensed C library libssh, which implements SSHv2 (and SSHv1) on client and server side, have announced the release of version 0.5.0. According to the developers, there has been a rewrite of "huge parts of the libssh internals" to allow the library to be completely asynchronous in the future.. This involved moving from a synchronous to an event-based network design. Other changes in 0.5.0 include prefixing all public functions with ssh_, completing Windows support, improved server support, additional unit tests and the addition of an asynchronous service request and a multi-platform ssh_getpass() function. The developers have also added a tutorial and other documentation, fixed a number of bugs and reduced memory leaks. The improvements in libssh reduce the differences between it and libssh2, a BSD-licensed library with similar goals. The link for this article located at H Security is no longer available. . Release 0.5.0 of libssh brings enhanced asynchronous capabilities and expanded features for network architecture and server compatibility.. libssh, Asynchronous Support, Multi-Platform Library, SSH Protocol. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.