Information disclosure in OpenSSH - CVE-2018-15919

 

Information disclosure in OpenSSH - CVE-2018-15919

Published: August 28, 2018 / Updated: August 29, 2018


Vulnerability identifier: #VU14548
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15919
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists due to insufficient validation of an authentication request packet when the Guide Star Server II (GSS2) component is used. A remote attacker can send an authentication request packet and access sensitive information, such as valid usernames.


Affected software

OpenSSH
openssh (Debian package)
pam_ssh_agent_auth
Opensuse
openEuler
Dynamic System Analysis (DSA) Preboot
EMC Cloud Tiering Appliance
Flex System Chassis Management Module (CMM)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2018-15919

Cybersecurity Help is currently unaware of any solutions addressing the vulnerability.

Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
pam_ssh_agent_auth - update to 0.10.3-9.1
Flex System Chassis Management Module (CMM) - update to 2pet18a-2.5.14a
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
EMC Cloud Tiering Appliance - update to 12.1.0.65

External References

Related Security Bulletins