This update for ssh-audit fixes the following issues:
ssh-audit was updated to version 2.5.0
* Fixed crash when running host key tests.
* Handles server connection failures more gracefully.
* Now prints JSON with indents when -jj is used (useful for debugging).
* Added MD5 fingerprints to verbose output.
* Added -d/--debug option for getting debugging output.
* Updated JSON output to include MD5 fingerprints. Note that this results
in a breaking change in the 'fingerprints' dictionary format.
* Updated OpenSSH 8.1 (and earlier) policies to include rsa-sha2-512 and
rsa-sha2-256.
* Added OpenSSH v8.6 & v8.7 policies.
* Added 3 new key exchanges:
+ gss-gex-sha1-eipGX3TCiQSrx573bT1o1Q= + gss-group1-sha1-eipGX3TCiQSrx573bT1o1Q= + gss-group14-sha1-eipGX3TCiQSrx573bT1o1Q= * Added 3 new MACs:
+ hmac-ripemd160-96
+ AEAD_AES_128_GCM
+ AEAD_AES_256_GCM
Update to version 2.4.0
* Added multi-threaded scanning...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP3:
zypper in -t patch openSUSE-2021-1390=1
- openSUSE Backports SLE-15-SP3 (noarch):
ssh-audit-2.5.0-bp153.2.3.1
https://www.suse.com/security/cve/CVE-2018-15473.html
Get the latest Linux and open source security news straight to your inbox.