mirror of
				https://github.com/jtesta/ssh-audit.git
				synced 2025-11-03 18:52:15 +01:00 
			
		
		
		
	Added version check for OpenSSH user enumeration (CVE-2018-15473). (#83)
This commit is contained in:
		@@ -66,6 +66,7 @@ class VersionVulnerabilityDB:  # pylint: disable=too-few-public-methods
 | 
			
		||||
            ['0.4.7', '0.5.2',  1, 'CVE-2012-4560', 7.5, 'cause DoS or execute arbitrary code (buffer overflow)'],
 | 
			
		||||
            ['0.4.7', '0.5.2',  1, 'CVE-2012-4559', 6.8, 'cause DoS or execute arbitrary code (double free)']],
 | 
			
		||||
        'OpenSSH': [
 | 
			
		||||
            ['1.0',     '7.7',     1, 'CVE-2018-15473', 5.3, 'enumerate usernames due to timing discrepencies'],
 | 
			
		||||
            ['7.2',     '7.2p2',   1, 'CVE-2016-6515',  7.8, 'cause DoS via long password string (crypt CPU consumption)'],
 | 
			
		||||
            ['1.2.2',   '7.2',     1, 'CVE-2016-3115',  5.5, 'bypass command restrictions via crafted X11 forwarding data'],
 | 
			
		||||
            ['5.4',     '7.1',     1, 'CVE-2016-1907',  5.0, 'cause DoS via crafted network traffic (out of bounds read)'],
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user