Oval Definition:oval:com.ubuntu.precise:def:20155600000
Revision Date:2015-08-02Version:1
Title:CVE-2015-5600 on Ubuntu 12.04 LTS (precise) - low.
Description:The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumption) via a long and duplicative list in the ssh -oKbdInteractiveDevices option, as demonstrated by a modified client that provides a different password for each pam element on this list.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2015-5600
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The 'openssh' package in precise was vulnerable but has been fixed (note: '1:5.9p1-5ubuntu1.6').
  • BACK