Re: POC and patch for the CVE-2018-15473

2019-05-13 Thread Brett Glass
My company has remained with FreeBSD 11 for now because we have encountered NIC driver stability problems under heavy loads with FreeBSD 12.0. As an ISP, we also endure constant brute force username and password guessing attacks, so a fix for this problem is of interest to us. Is the FreeBSD

Re: POC and patch for the CVE-2018-15473

2019-05-13 Thread Gareth de Vaux
On Mon 2019-05-13 (10:32), Brett Glass wrote: > On my FreeBSD 11-STABLE boxes, the "distinfo" file for the > "openssh-portable" port shows the version as "openssh-7.9p1". So, > this is not 7.8 (which was tested with 12.0, at least, if not 11.x) > and also has not been specifically tailored for F

Re: POC and patch for the CVE-2018-15473

2019-05-13 Thread Brett Glass
At 10:13 AM 5/13/2019, you wrote: On Mon 2019-05-13 (09:51), Brett Glass wrote: > Is the FreeBSD port of OpenSSH 7.8 available for FreeBSD 11-STABLE > from the ports collection and as a binary package? If not, shouldn't it be? Yes, you can use the original at /usr/ports/security/openssh-portabl

Re: POC and patch for the CVE-2018-15473

2019-05-13 Thread Gareth de Vaux
On Mon 2019-05-13 (09:51), Brett Glass wrote: > Is the FreeBSD port of OpenSSH 7.8 available for FreeBSD 11-STABLE > from the ports collection and as a binary package? If not, shouldn't it be? Yes, you can use the original at /usr/ports/security/openssh-portable __

Re: POC and patch for the CVE-2018-15473

2019-05-13 Thread Brett Glass
My company has remained with FreeBSD 11 for now because we have encountered NIC driver stability problems under heavy loads with FreeBSD 12.0. As an ISP, we also endure constant brute force username and password guessing attacks, so a fix for this problem is of interest to us. Is the FreeBSD

Re: POC and patch for the CVE-2018-15473

2019-04-25 Thread Dag-Erling Smørgrav
Brahmanand Reddy writes: > CVE-2018-15473 is a "user existence oracle bug which does not meet our > criteria for security advisories". > > You mean this vulnerability which will impact/affects only for Oracle > base? . kindly  confirm. An oracle vulnerability is a type of information disclosure b

Re: POC and patch for the CVE-2018-15473

2019-04-24 Thread Cameron, Frank J
Brahmanand Reddy wrote: > CVE-2018-15473 is a "user existence oracle bug which does not meet our > criteria for security advisories". > > You mean this vulnerability which will impact/affects only for Oracle > base? kindly confirm. "Oracle" in the ancient Greek sense of a person through whom a d

Re: POC and patch for the CVE-2018-15473

2019-04-24 Thread Brahmanand Reddy
Thank you! CVE-2018-15473 is a "user existence oracle bug which does not meet our criteria for security advisories". You mean this vulnerability which will impact/affects only for Oracle base? . kindly confirm. On Wed, Apr 24, 2019 at 3:54 PM Dag-Erling Smørgrav wrote: > Brahmanand Reddy wri

Re: POC and patch for the CVE-2018-15473

2019-04-24 Thread Dag-Erling Smørgrav
Brahmanand Reddy writes: > regarding the CVE-2018-15473 dint find find official patch from the openssh > on freebsd OS base. CVE-2018-15473 is a user existence oracle bug which does not meet our criteria for security advisories. FreeBSD 12 has OpenSSH 7.8, which is patched. FreeBSD 11 has OpenS

POC and patch for the CVE-2018-15473

2019-04-23 Thread Brahmanand Reddy
Dear experts, regarding the CVE-2018-15473 dint find find official patch from the openssh on freebsd OS base. i found following relevant patch on openBsd based and applied on freeBsd. https://github.com/openbsd/src/commit/779974d35b4859c07bc3cb8a12c74b43b0a7d1e0 Could you please confirm the this