Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2018.0204
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2018-0204)
Resumen:The remote host is missing an update for the 'python-paramiko' package(s) announced via the MGASA-2018-0204 advisory.
Descripción:Summary:
The remote host is missing an update for the 'python-paramiko' package(s) announced via the MGASA-2018-0204 advisory.

Vulnerability Insight:
A flaw was found in the implementation of `transport.py` in Paramiko,
which did not properly check whether authentication was completed before
processing other requests. A customized SSH client could simply skip the
authentication step (CVE-2018-7750).

This flaw is a user authentication bypass in the SSH Server
functionality of Paramiko. Where Paramiko is used only for its
client-side functionality (e.g. `paramiko.SSHClient`), the vulnerability
is not exposed and thus cannot be exploited.

Affected Software/OS:
'python-paramiko' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2018-7750
BugTraq ID: 103713
http://www.securityfocus.com/bid/103713
https://www.exploit-db.com/exploits/45712/
https://lists.debian.org/debian-lts-announce/2018/10/msg00018.html
https://lists.debian.org/debian-lts-announce/2021/12/msg00025.html
RedHat Security Advisories: RHSA-2018:0591
https://access.redhat.com/errata/RHSA-2018:0591
RedHat Security Advisories: RHSA-2018:0646
https://access.redhat.com/errata/RHSA-2018:0646
RedHat Security Advisories: RHSA-2018:1124
https://access.redhat.com/errata/RHSA-2018:1124
RedHat Security Advisories: RHSA-2018:1125
https://access.redhat.com/errata/RHSA-2018:1125
RedHat Security Advisories: RHSA-2018:1213
https://access.redhat.com/errata/RHSA-2018:1213
RedHat Security Advisories: RHSA-2018:1274
https://access.redhat.com/errata/RHSA-2018:1274
RedHat Security Advisories: RHSA-2018:1328
https://access.redhat.com/errata/RHSA-2018:1328
RedHat Security Advisories: RHSA-2018:1525
https://access.redhat.com/errata/RHSA-2018:1525
RedHat Security Advisories: RHSA-2018:1972
https://access.redhat.com/errata/RHSA-2018:1972
https://usn.ubuntu.com/3603-1/
https://usn.ubuntu.com/3603-2/
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.