CVE-2018-15473 openssh: User enumeration via malformed packets in authentication requests

CVE ID

CVE-2018-15473

DESCRIPTION

A user enumeration vulnerability flaw was found in OpenSSH, though version 7.7. The vulnerability occurs by not delaying bailout for an invalid authenticated user until after the packet containing the request has been fully parsed. The highest threat from this vulnerability is to data confidentiality.

RESOLUTION

  • CentOS6 Unitrends' appliances (physical and/or virtual), fixed in Unitrends software release-10.3.8-4.  Please upgrade to latest release.
  • CentOS7 Unitrends' appliances (physical and/or virtual) do not have a fix for this CVE as of the current release (10.4.3).

LINK TO ADVISORIES

Have more questions?

Contact us

Was this article helpful?
0 out of 0 found this helpful

Provide feedback for the Documentation team!

Browse this section