PT-2018-1486 · Openssh+6 · Openssh+6

Publicado

2018-08-17

·

Atualizado

2026-03-10

·

CVE-2018-15473

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSH versions 7.7 and earlier
Description The issue is related to a user enumeration vulnerability. It is caused by the server's different responses to authentication requests when valid and invalid user accounts are present. An attacker can exploit this by sending specially crafted authentication requests to identify existing user accounts. The vulnerability is related to files auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
Recommendations For OpenSSH versions 7.7 and earlier, consider updating to a version later than 7.7 to resolve the issue. As a temporary workaround, consider restricting access to the authentication mechanism to minimize the risk of exploitation. Avoid using the authentication features in a way that could reveal user account information until the issue is resolved.

Exploit

Correção

Information Disclosure

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2024_1130
ALSA-2024_1150
ALSA-2025_16880
ALT-PU-2018-2222
ALT-PU-2018-2598
ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2018-01037
CESA-2019_0711
CESA-2019_2143
CVE-2018-15473
DLA-1474-1
DLA-1476-1
DSA-4280-1
ELSA-2019-0711
ELSA-2019-2143
MGASA-2018-0363
OPENSUSE-SU-2018_3801-1
OPENSUSE-SU-2018_3946-1
OPENSUSE-SU-2021:1383-1
OPENSUSE-SU-2021:1390-1
OPENSUSE-SU-2021_1383-1
OPENSUSE-SU-2024:11407-1
RHSA-2019:0711
RHSA-2019:2143
RHSA-2019_0711
RHSA-2019_2143
SSHLOGINENUMERATIONCVE2018
SUSE-SU-2018:3540-1
SUSE-SU-2018:3686-1
SUSE-SU-2018:3768-1
SUSE-SU-2018:3776-1
SUSE-SU-2018:3776-2
SUSE-SU-2018:3781-1
SUSE-SU-2018:3910-1
SUSE-SU-2018_3540-1
SUSE-SU-2018_3686-1
SUSE-SU-2018_3768-1
SUSE-SU-2018_3776-1
SUSE-SU-2018_3776-2
SUSE-SU-2018_3781-1
SUSE-SU-2018_3910-1
USN-3809-1
USN-3809-2

Produtos afetados

Alt Linux
Centos
Ibm Aix
Openssh
Red Hat
Suse
Ubuntu