CVE-2018-15599
Dashboard / Vulnerabilities / CVE-2018-15599
Summary:
Details: The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a similar issue to CVE-2018-15473 in an unrelated codebase.
References: https://matt.ucc.asn.au/dropbear/CHANGES, http://lists.ucc.gu.uwa.edu.au/pipermail/dropbear/2018q3/002108.html, http://lists.ucc.gu.uwa.edu.au/pipermail/dropbear/2018q3/002109.html, https://lists.debian.org/debian-lts-announce/2018/08/msg00026.html, https://old.reddit.com/r/blackhat/comments/97ywnm/openssh_username_enumeration/e4e05n2/
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
