The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a similar issue to CVE-2018-15473 in an unrelated codebase. References: http://lists.ucc.gu.uwa.edu.au/pipermail/dropbear/2018q3/002108.html Upstream Patch: https://secure.ucc.asn.au/hg/dropbear/rev/5d2d1021ca00
Created dropbear tracking bugs for this issue: Affects: epel-all [bug 1623177] Affects: fedora-all [bug 1623176]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.