5
CVSSv2

CVE-2018-3737

Published: 07/06/2018 Updated: 30/01/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

joyent sshpk

Vendor Advisories

Synopsis Moderate: rh-nodejs8-nodejs security update Type/Severity Security Advisory: Moderate Topic An update for rh-nodejs8-nodejs is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ...
Debian Bug report logs - #901093 node-sshpk: CVE-2018-3737 Package: src:node-sshpk; Maintainer for src:node-sshpk is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 8 Jun 2018 21:12:04 UTC Severity: important Tags: fixed-u ...

Github Repositories

🛡 Collection about Node.js CVE and PoC

node-cve Collection about Nodejs CVE and PoC 收集的一些关于 Nodejs 的 CVE 和 PoC Indexes 索引 CVE-2018-3728 name: hoek Prototype pollution attack CVE-2018-3737 name: sshpk sshpk is vulnerable to ReDoS when parsing crafted invalid public keys Reference 参考 ReDoS: Regular expression Denial of Service wwwowasporg/indexphp/Regular_expression_Deni