CVE-2018-15599

The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a similar issue to CVE-2018-15473 in an unrelated codebase.
Configurations

Configuration 1

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:dropbear_ssh_project:dropbear_ssh:*:*:*:*:*:*:*:*

Information

Published : 2018-08-21 01:29

Updated : 2020-12-30 08:15


NVD link : CVE-2018-15599

Mitre link : CVE-2018-15599

Products Affected
No products.
CWE