![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.854233 |
Category: | SuSE Local Security Checks |
Title: | openSUSE: Security Advisory for ssh-audit (openSUSE-SU-2021:1383-1) |
Summary: | The remote host is missing an update for the 'ssh-audit'; package(s) announced via the openSUSE-SU-2021:1383-1 advisory. |
Description: | Summary: The remote host is missing an update for the 'ssh-audit' package(s) announced via the openSUSE-SU-2021:1383-1 advisory. Vulnerability Insight: This update for ssh-audit fixes the following issues: ssh-audit was updated to version 2.5.0 * Fixed crash when running host key tests. * Handles server connection failures more gracefully. * Now prints JSON with indents when -jj is used (useful for debugging). * Added MD5 fingerprints to verbose output. * Added -d/--debug option for getting debugging output. * Updated JSON output to include MD5 fingerprints. Note that this results in a breaking change in the ' fingerprints' dictionary format. * Updated OpenSSH 8.1 (and earlier) policies to include rsa-sha2-512 and rsa-sha2-256. * Added OpenSSH v8.6 & v8.7 policies. * Added 3 new key exchanges: + gss-gex-sha1-eipGX3TCiQSrx573bT1o1Q== + gss-group1-sha1-eipGX3TCiQSrx573bT1o1Q== + gss-group14-sha1-eipGX3TCiQSrx573bT1o1Q== * Added 3 new MACs: + hmac-ripemd160-96 + AEAD_AES_128_GCM + AEAD_AES_256_GCM Update to version 2.4.0 * Added multi-threaded scanning support. * Added version check for OpenSSH user enumeration (CVE-2018-15473). * Added deprecation note to host key types based on SHA-1. * Added extra warnings for SSHv1. * Added built-in hardened OpenSSH v8.5 policy. * Upgraded warnings to failures for host key types based on SHA-1 * Fixed crash when receiving unexpected response during host key test. * Fixed hang against older Cisco devices during host key test & gex test. * Fixed improper termination while scanning multiple targets when one target returns an error. * Dropped support for Python 3.5 (which reached EOL in Sept.2020) * Added 1 new key exchange: sntrup761x25519-sha512(a)openssh.com. Update to version 2.3.1 * Now parses public key sizes for rsa-sha2-256-cert-v01(a)openssh.com and rsa-sha2-512-cert-v01(a)openssh.com host key types. * Flag ssh-rsa-cert-v01(a)openssh.com as a failure due to SHA-1 hash. * Fixed bug in recommendation output which suppressed some algorithms inappropriately. * Built-in policies now include CA key requirements (if certificates are in use). * Lookup function (--lookup) now performs case-insensitive lookups of similar algorithms. * Migrated pre-made policies from external files to internal database. * Split single 3,500 line script into many files (by class). * Added setup.py support * Added 1 new cipher: des-cbc(a)ssh.com. Update to version 2.3.0 The highlight of this release is support for policy scanning (th ... Description truncated. Please see the references for more information. Affected Software/OS: 'ssh-audit' package(s) on openSUSE Leap 15.2. Solution: Please install the updated package(s). CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2018-15473 BugTraq ID: 105140 http://www.securityfocus.com/bid/105140 Debian Security Information: DSA-4280 (Google Search) https://www.debian.org/security/2018/dsa-4280 https://www.exploit-db.com/exploits/45210/ https://www.exploit-db.com/exploits/45233/ https://www.exploit-db.com/exploits/45939/ https://security.gentoo.org/glsa/201810-03 http://www.openwall.com/lists/oss-security/2018/08/15/5 https://bugs.debian.org/906236 https://github.com/openbsd/src/commit/779974d35b4859c07bc3cb8a12c74b43b0a7d1e0 https://www.oracle.com/security-alerts/cpujan2020.html https://lists.debian.org/debian-lts-announce/2018/08/msg00022.html RedHat Security Advisories: RHSA-2019:0711 https://access.redhat.com/errata/RHSA-2019:0711 RedHat Security Advisories: RHSA-2019:2143 https://access.redhat.com/errata/RHSA-2019:2143 http://www.securitytracker.com/id/1041487 https://usn.ubuntu.com/3809-1/ |
Copyright | Copyright (C) 2021 Greenbone Networks GmbH |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |