Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

libssh in Wireshark 2.x for macOS susceptible to CVE-2018-10933 exploit?

Can anyone confirm whether the libssh libraries used in Wireshark 2.x for macOS are vulnerable, or whether they're used in a fashion that would allow for the exploit as described here? LIBSSH_VERSION=0.7.4 appears in macos-setup.sh, and the patched version listed in CVE-2018-10933 is 0.7.6.