REDHAT-BUG-1619063: Low severity openssh vulnerability
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
Upstream Patch:
https://github.com/openbsd/src/commit/779974d35b4859c07bc3cb8a12c74b43b0a7d1e0
Reference:
http://www.openwall.com/lists/oss-security/2018/08/15/5
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1619063?
The severity of REDHAT-BUG-1619063 is considered to be critical due to its impact on user enumeration.
How do I fix REDHAT-BUG-1619063?
To fix REDHAT-BUG-1619063, upgrade OpenSSH to version 7.8 or later where the vulnerability is patched.
What systems are affected by REDHAT-BUG-1619063?
REDHAT-BUG-1619063 affects OpenSSH versions up to and including 7.7.
What causes the vulnerability in REDHAT-BUG-1619063?
The vulnerability in REDHAT-BUG-1619063 is caused by insufficient delay in responses to invalid authentication attempts.
What type of vulnerability is REDHAT-BUG-1619063?
REDHAT-BUG-1619063 is a user enumeration vulnerability that can be exploited by attackers to validate usernames.