sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HJoyent Sshpk
APPJoyent≤ 1.13.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2020-27678CRITICAL9.8PL ✓same vendor
Buffer overflow w PAM illumos — podatność w funkcji parse_user_name
CVE-2020-7712HIGH7.2same vendor
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup...
CVE-2017-16005HIGH7.5same vendor
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-s...
CVE-2018-1171HIGH7.0same vendor
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS...
CVE-2018-1166HIGH7.8same vendor
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS...