Re: POC and patch for the CVE-2018-15473

2019-04-24 Thread Cameron, Frank J
Brahmanand Reddy wrote: > CVE-2018-15473 is a "user existence oracle bug which does not meet our > criteria for security advisories". > > You mean this vulnerability which will impact/affects only for Oracle > base? kindly confirm. "Oracle" in the ancient Greek sense of a person through whom a d

Re: POC and patch for the CVE-2018-15473

2019-04-24 Thread Brahmanand Reddy
Thank you! CVE-2018-15473 is a "user existence oracle bug which does not meet our criteria for security advisories". You mean this vulnerability which will impact/affects only for Oracle base? . kindly confirm. On Wed, Apr 24, 2019 at 3:54 PM Dag-Erling Smørgrav wrote: > Brahmanand Reddy wri

Re: POC and patch for the CVE-2018-15473

2019-04-24 Thread Dag-Erling Smørgrav
Brahmanand Reddy writes: > regarding the CVE-2018-15473 dint find find official patch from the openssh > on freebsd OS base. CVE-2018-15473 is a user existence oracle bug which does not meet our criteria for security advisories. FreeBSD 12 has OpenSSH 7.8, which is patched. FreeBSD 11 has OpenS