Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Mageia 6 MGASA-2018-0363: OpenSSH User Enumeration Threat

mageia
Calendar Grey August 31, 2018
Dist Mageia Esm H88
MGASA-2018-0363 - Updated openssh packages fix security vulnerability Publication date: 31 Aug 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has be...

Summary

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c (CVE-2018-15473).

References

- https://bugs.mageia.org/show_bug.cgi?id=23452

- https://openwall.com/lists/oss-security/2018/08/15/5

- https://sekurak.pl/openssh-users-enumeration-cve-2018-15473/

- https://www.cve.org/CVERecord?id=CVE-2018-15473

Resolution

SRPMS

- 6/core/openssh-7.5p1-2.2.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 31 Aug 2018
URL: https://advisories.mageia.org/MGASA-2018-0363.html
Type: security
CVE: CVE-2018-15473

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here