#VU14298 Improper input validation in sshpk - CVE-2018-3737
Published: August 8, 2018 / Updated: August 9, 2018
sshpk
Joyent, Inc.
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to the use of certain regular expressions for parsing OpenSSH-format public keys. A remote attacker can create a custom public key to be parsed, trigger increases in runtime and cause the service to crash.