Candidate: CVE-2018-3737 PublicDate: 2018-06-07 02:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3737 https://github.com/joyent/node-sshpk/issues/44 https://github.com/joyent/node-sshpk/commit/46065d38a5e6d1bccf86d3efb2fb83c14e3f9957 Description: sshpk is vulnerable to ReDoS when parsing crafted invalid public keys. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=901093 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_node-sshpk: upstream_node-sshpk: released (1.13.1+dfsg-2) precise/esm_node-sshpk: DNE trusty_node-sshpk: ignored (out of standard support) trusty/esm_node-sshpk: DNE xenial_node-sshpk: DNE bionic_node-sshpk: needs-triage focal_node-sshpk: not-affected (1.16.1+dfsg-2) groovy_node-sshpk: not-affected hirsute_node-sshpk: not-affected impish_node-sshpk: not-affected jammy_node-sshpk: not-affected devel_node-sshpk: not-affected