Back to search
CVE-2018-15473
Published: Aug 17, 2018
Modified: Dec 17, 2025
PUBLISHED
Description
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
GLSA-201810-03
vendor-advisory
1041487
vdb-entry
45233
exploit
45210
exploit
USN-3809-1
vendor-advisory
105140
vdb-entry
DSA-4280
vendor-advisory
45939
exploit
RHSA-2019:0711
vendor-advisory
RHSA-2019:2143
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now