guix-patches
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[bug#32451] [PATCH] gnu: openssh: Don't allow remote username enumeratio


From: Ludovic Courtès
Subject: [bug#32451] [PATCH] gnu: openssh: Don't allow remote username enumeration
Date: Thu, 23 Aug 2018 16:48:28 +0200
User-agent: Gnus/5.13 (Gnus v5.13) Emacs/26.1 (gnu/linux)

Leo Famulari <address@hidden> skribis:

> The bug was assigned CVE-2018-15473.
>
> This patch is basically identical to the one being used by Debian. I
> tested with the POC from oss-sec [0], which required some changes to the
> Paramiko package.
>
> Pushed as 6cd2c4a83cc2baa387d04979b489bee2429cc39d

Thank you!

Ludo’.





reply via email to

[Prev in Thread] Current Thread [Next in Thread]