CVE-2018-3737: High severity joyent sshpk vulnerability
A flaw was found in sshpk versions before 1.14.1. The regular expressions used for parsing OpenSSH-format public keys in sshpk are resulting in exponential increases in runtime when parsing maliciously constructed inputs.
References: https://github.com/joyent/node-sshpk/issues/44
Pacth: https://github.com/joyent/node-sshpk/commit/46065d38a5e6d1bccf86d3efb2fb83c14e3f9957
Other sources
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-3737?
CVE-2018-3737 is a vulnerability in sshpk that allows for ReDoS attacks when parsing crafted invalid public keys.
How severe is CVE-2018-3737?
CVE-2018-3737 has a severity rating of high, with a severity value of 7.5.
What software is affected by CVE-2018-3737?
The following software versions are affected by CVE-2018-3737: sshpk 1.14.1, sshpk 1.3.2, and Joyent Sshpk up to version 1.13.1.
How can I fix CVE-2018-3737?
To fix CVE-2018-3737, update sshpk to version 1.14.1 (for sshpk 1.14.1), version 1.3.2 (for sshpk 1.3.2), or a version later than 1.13.1 (for Joyent Sshpk).
Where can I find more information about CVE-2018-3737?
You can find more information about CVE-2018-3737 at the following references: [GitHub Issue](https://github.com/joyent/node-sshpk/issues/44), [GitHub Commit](https://github.com/joyent/node-sshpk/commit/46065d38a5e6d1bccf86d3efb2fb83c14e3f9957), [HackerOne Report](https://hackerone.com/reports/319593).