[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
bug#32451: [PATCH] gnu: openssh: Don't allow remote username enumeration
From: |
Leo Famulari |
Subject: |
bug#32451: [PATCH] gnu: openssh: Don't allow remote username enumeration |
Date: |
Tue, 21 Aug 2018 11:17:26 -0400 |
User-agent: |
Mutt/1.10.1 (2018-07-13) |
The bug was assigned CVE-2018-15473.
This patch is basically identical to the one being used by Debian. I
tested with the POC from oss-sec [0], which required some changes to the
Paramiko package.
Pushed as 6cd2c4a83cc2baa387d04979b489bee2429cc39d
[0] http://seclists.org/oss-sec/2018/q3/125