Red Hat Bugzilla – Bug 1623184
CVE-2018-15919 openssh: User enumeration via malformed packets in authentication requests
Last modified: 2018-10-24 04:47:33 EDT
A flaw was found in OpenSSH versions from 5.9 (September 6, 2011) to the recently released 7.8 (August 24, 2018), inclusive. A remotely observable behaviour in auth-gss2.c could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. Similar to CVE-2018-15473 (it is not a timing attack) References: http://seclists.org/oss-sec/2018/q3/180
Created openssh tracking bugs for this issue: Affects: fedora-all [bug 1623185]