CVE-2018-10933: Critical severity libssh libssh vulnerability
Published Oct 16, 2018
·Updated
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
Affected Software
17 affected componentsFixes available
debian/libssh<=0.6.3-4+deb8u2, <=0.7.3-2, <=0.7.3-1
0.8.4-10.7.3-2+deb9u1
libssh libssh>=0.6.0<0.7.6
libssh libssh>=0.8.0<0.8.4
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Debian Debian Linux=8.0
Debian Debian Linux=9.0
redhat Enterprise Linux=7.0
NetApp Oncommand Unified Manager Windows>=7.3
NetApp Oncommand Unified Manager Vsphere>=9.4
NetApp OnCommand Workflow Automation
NetApp Snapcenter
NetApp Storage Automation Store
Oracle MySQL Workbench<=8.0.13
debian/libssh
0.9.8-0+deb11u10.9.8-0+deb11u20.10.6-0+deb12u20.10.6-0+deb12u10.11.2-1+deb13u10.11.3-1
Remediation
Event History
Oct 17, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:46 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·04:00 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·04:00 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2018-10933?
CVE-2018-10933 is a vulnerability found in libssh's server-side state machine before versions 0.7.6 and 0.8.4.
2
How does CVE-2018-10933 work?
CVE-2018-10933 allows a malicious client to create channels without authentication, leading to unauthorized access.
3
What is the severity of CVE-2018-10933?
The severity of CVE-2018-10933 is critical with a CVSS score of 9.1.
4
Which software versions are affected by CVE-2018-10933?
Versions 0.6.0 to 0.7.6 and 0.8.0 to 0.8.4 of libssh are affected by CVE-2018-10933.
5
How can I fix CVE-2018-10933?
To fix CVE-2018-10933, update libssh to version 0.7.6 or 0.8.4 or later.