2018-08-28
ALT-BU-2018-3427-1
Branch c8 update bulletin.
Closed vulnerabilities
Published: 2018-08-17
BDU:2018-01037
Уязвимость средства криптографической защиты OpenSSH, связанная с различной реакцией сервера на запросы аутентификации, позволяющая нарушителю выявить существующие учетные записи пользователей
Severity: HIGH (7.5)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References:
Published: 2018-08-17
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
Severity: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References:
- http://www.openwall.com/lists/oss-security/2018/08/15/5
- http://www.openwall.com/lists/oss-security/2018/08/15/5
- 105140
- 105140
- 1041487
- 1041487
- RHSA-2019:0711
- RHSA-2019:0711
- RHSA-2019:2143
- RHSA-2019:2143
- https://bugs.debian.org/906236
- https://bugs.debian.org/906236
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://github.com/openbsd/src/commit/779974d35b4859c07bc3cb8a12c74b43b0a7d1e0
- https://github.com/openbsd/src/commit/779974d35b4859c07bc3cb8a12c74b43b0a7d1e0
- [debian-lts-announce] 20180821 [SECURITY] [DLA-1474-1] openssh security update
- [debian-lts-announce] 20180821 [SECURITY] [DLA-1474-1] openssh security update
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0011
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0011
- GLSA-201810-03
- GLSA-201810-03
- https://security.netapp.com/advisory/ntap-20181101-0001/
- https://security.netapp.com/advisory/ntap-20181101-0001/
- USN-3809-1
- USN-3809-1
- DSA-4280
- DSA-4280
- 45210
- 45210
- 45233
- 45233
- 45939
- 45939
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpujan2020.html