Information disclosure in OpenSSH - CVE-2018-15919
Published: August 28, 2018 / Updated: August 29, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to insufficient validation of an authentication request packet when the Guide Star Server II (GSS2) component is used. A remote attacker can send an authentication request packet and access sensitive information, such as valid usernames.
Affected software
openssh (Debian package)
pam_ssh_agent_auth
Opensuse
openEuler
Dynamic System Analysis (DSA) Preboot
EMC Cloud Tiering Appliance
Flex System Chassis Management Module (CMM)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
How to mitigate CVE-2018-15919
pam_ssh_agent_auth - update to 0.10.3-9.1
Flex System Chassis Management Module (CMM) - update to 2pet18a-2.5.14a
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
EMC Cloud Tiering Appliance - update to 12.1.0.65
External References
Related Security Bulletins
- Information disclosure in OpenSSH
- OpenSUSE Linux update for openssh
- Information disclosure in Debian openssh package
- Multiple vulnerabilities in Dell EMC Unity Family
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance Family
- openEuler 20.03 LTS update for openssh
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)
- Multiple vulnerabilities in IBM Dynamic System Analysis (DSA) Preboot