cve/2010/CVE-2010-4478.md

44 lines
2.0 KiB
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2010-4478](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4478)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.
### POC
#### Reference
- https://bugzilla.redhat.com/show_bug.cgi?id=659297
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/DButter/whitehat_public
- https://github.com/Dokukin1/Metasploitable
- https://github.com/George210890/13-01.md
- https://github.com/Heshamshaban001/Kioptix-level-1-walk-through
- https://github.com/Heshamshaban001/Metasploitable1-walkthrough
- https://github.com/Heshamshaban001/Metasploitable2-Walk-through
- https://github.com/Iknowmyname/Nmap-Scans-M2
- https://github.com/Ivashka80/13-01_Osnova
- https://github.com/NikulinMS/13-01-hw
- https://github.com/PavelKondakov22/13-1
- https://github.com/SashkaSer/vulnerabilitys
- https://github.com/SergeiShulga/13_1
- https://github.com/SergeyM90/Atack1
- https://github.com/VictorSum/13.1
- https://github.com/Wernigerode23/Uiazvimosty
- https://github.com/Zhivarev/13-01-hw
- https://github.com/kaio6fellipe/ssh-enum
- https://github.com/ovchdmitriy01/13-1
- https://github.com/scmanjarrez/CVEScannerV2
- https://github.com/scmanjarrez/test
- https://github.com/smabramov/Vulnerabilities-and-attacks-on-information-systems
- https://github.com/syadg123/pigat
- https://github.com/teamssix/pigat
- https://github.com/vioas/Vulnerabilities-and-attacks-on-information-systems
- https://github.com/ya-haf/Metasploitable
- https://github.com/zzzWTF/db-13-01