OpenSSH: User enumeration vulnerability — GLSA 201810-03

A vulnerability in OpenSSH might allow remote attackers to determine valid usernames.

Affected packages

net-misc/openssh on all architectures
Affected versions < 7.7_p1-r8
Unaffected versions >= 7.7_p1-r8

Background

OpenSSH is a complete SSH protocol implementation that includes SFTP client and server support.

Description

It was discovered that OpenSSH was prone to a user enumeration vulnerability.

Impact

A remote attacker could conduct user enumeration.

Workaround

There is no known workaround at this time.

Resolution

All OpenSSH users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-misc/openssh-7.7_p1-r8"
 

References

Release date
October 06, 2018

Latest revision
October 06, 2018: 1

Severity
low

Exploitable
remote

Bugzilla entries