Description
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1474-1 | openssh security update |
Debian DLA |
DLA-1476-1 | dropbear security update |
Debian DSA |
DSA-4280-1 | openssh security update |
Ubuntu USN |
USN-3809-1 | OpenSSH vulnerabilities |
References
History
Wed, 17 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Netapp
Subscribe
Aff Baseboard Management Controller
Subscribe
Cloud Backup
Subscribe
Clustered Data Ontap
Subscribe
Cn1610
Subscribe
Cn1610 Firmware
Subscribe
Data Ontap
Subscribe
Data Ontap Edge
Subscribe
Fas Baseboard Management Controller
Subscribe
Oncommand Unified Manager
Subscribe
Ontap Select Deploy
Subscribe
Service Processor
Subscribe
Steelstore Cloud Integrated Storage
Subscribe
Storage Replication Adapter
Subscribe
Vasa Provider
Subscribe
Virtual Storage Console
Subscribe
Openbsd
Subscribe
Openssh
Subscribe
Oracle
Subscribe
Sun Zfs Storage Appliance Kit
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Workstation
Subscribe
Siemens
Subscribe
Scalance X204rna
Subscribe
Scalance X204rna Firmware
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-17T21:22:47.283Z
Reserved: 2018-08-17T00:00:00.000Z
Link: CVE-2018-15473
Updated: 2024-08-05T09:54:03.508Z
Status : Modified
Published: 2018-08-17T19:29:00.223
Modified: 2025-12-17T22:15:54.557
Link: CVE-2018-15473
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN