POC and patch for the CVE-2018-15473

Brahmanand Reddy brahma.gdb at gmail.com
Wed Apr 24 11:27:52 UTC 2019


Thank you!

CVE-2018-15473 is a "user existence oracle bug which does not meet our
criteria for security advisories".

You mean this vulnerability which will impact/affects only for Oracle base?
. kindly  confirm.

On Wed, Apr 24, 2019 at 3:54 PM Dag-Erling Smørgrav <des at freebsd.org> wrote:

> Brahmanand Reddy <brahma.gdb at gmail.com> writes:
> > regarding the CVE-2018-15473 dint find find official patch from the
> openssh
> > on freebsd OS base.
>
> CVE-2018-15473 is a user existence oracle bug which does not meet our
> criteria for security advisories.
>
> FreeBSD 12 has OpenSSH 7.8, which is patched.  FreeBSD 11 has OpenSSH
> 7.5, which is not.
>
> DES
> --
> Dag-Erling Smørgrav - des at FreeBSD.org
>


More information about the freebsd-security mailing list