Information disclosure in OpenSSH - CVE-2018-15919
Published: August 28, 2018 / Updated: August 29, 2018
OpenSSH
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to insufficient validation of an authentication request packet when the Guide Star Server II (GSS2) component is used. A remote attacker can send an authentication request packet and access sensitive information, such as valid usernames.