CVE-2018-15919 PUBLISHED

Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a vulnerability.'

EPSS 2.08% · 83.9th percentile

Risk Scores

EPSS Score
2.08%
83.9th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSopenssh-ssh11:7.5p1-9build1, 1:7.5p1-9, 0
Ubuntu:20.04:LTSopenssh-ssh10, 1:7.5p1-11build1
Ubuntu:Pro:18.04:LTSopenssh1:7.6p1-4ubuntu0.5, 1:7.6p1-4ubuntu0.3, 1:7.6p1-4ubuntu0.2
Ubuntu:Pro:16.04:LTSopenssh1:7.2p2-4ubuntu2.7, 0, 1:6.9p1-2
Ubuntu:Pro:14.04:LTSopenssh1:6.6p1-2ubuntu2.4, 1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.11
Ubuntu:20.04:LTSopenssh1:8.2p1-4ubuntu0.11, 1:8.2p1-4ubuntu0.12, 1:8.2p1-4ubuntu0.13

Timeline

References

Open in Interactive Console →