A vulnerability was found in libsshs server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
This weakness has been deprecated because it covered redundant concepts already described in CWE-287.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libssh | Libssh | 0.6.0 (including) | 0.7.6 (excluding) |
| Libssh | Libssh | 0.8.0 (including) | 0.8.4 (excluding) |
| Red Hat Enterprise Linux 7 Extras | RedHat | cockpit-0:176-4.el7 | * |
| Red Hat Enterprise Linux 7 Extras | RedHat | libssh-0:0.7.1-7.el7 | * |
| Libssh | Ubuntu | bionic | * |
| Libssh | Ubuntu | cosmic | * |
| Libssh | Ubuntu | devel | * |
| Libssh | Ubuntu | esm-infra/bionic | * |
| Libssh | Ubuntu | esm-infra/xenial | * |
| Libssh | Ubuntu | trusty | * |
| Libssh | Ubuntu | xenial | * |