PT-2018-13107 · Dropbear+1 · Dropbear+1
Dbzjegrw8O
+1
·
Published
2018-08-20
·
Updated
2024-06-15
·
CVE-2018-15599
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dropbear versions prior to 2018.76
Description
The issue is related to a user enumeration problem in the recv msg userauth request function. This function is located in svr-auth.c and is prone to a vulnerability because the validity of usernames affects how certain fields in SSH MSG USERAUTH messages are handled.
Recommendations
For Dropbear versions prior to 2018.76, update to version 2018.76 or later to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Dropbear