Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-0711

Опубликовано: 10 апр. 2019
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2019-0711: openssh security update (LOW)

[5.3p1-124]

  • Fix for CVE-2018-15473: User enumeration via malformed packets in authentication requests

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

openssh

5.3p1-124.el6_10

openssh-askpass

5.3p1-124.el6_10

openssh-clients

5.3p1-124.el6_10

openssh-ldap

5.3p1-124.el6_10

openssh-server

5.3p1-124.el6_10

pam_ssh_agent_auth

0.9.3-124.el6_10

Oracle Linux i686

openssh

5.3p1-124.el6_10

openssh-askpass

5.3p1-124.el6_10

openssh-clients

5.3p1-124.el6_10

openssh-ldap

5.3p1-124.el6_10

openssh-server

5.3p1-124.el6_10

pam_ssh_agent_auth

0.9.3-124.el6_10

Связанные CVE

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 7 лет назад

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

CVSS3: 5.3
redhat
больше 7 лет назад

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

CVSS3: 5.3
nvd
около 7 лет назад

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

CVSS3: 5.3
debian
около 7 лет назад

OpenSSH through 7.7 is prone to a user enumeration vulnerability due t ...

suse-cvrf
около 4 лет назад

Security update for ssh-audit