PublicDateAtUSN: 2015-08-02 Candidate: CVE-2015-5600 PublicDate: 2015-08-03 01:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5600 http://seclists.org/fulldisclosure/2015/Jul/92 https://kingcope.wordpress.com/2015/07/16/openssh-keyboard-interactive-authentication-brute-force-vulnerability-maxauthtries-bypass/ https://ubuntu.com/security/notices/USN-2710-1 Description: The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumption) via a long and duplicative list in the ssh -oKbdInteractiveDevices option, as demonstrated by a modified client that provides a different password for each pam element on this list. Ubuntu-Description: Notes: tyhicks> Only affects systems with KbdInteractiveAuthentication set to 'yes'. By default, that option is set to 'no' in Ubuntu. Bugs: Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: Patches_openssh: upstream: http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/auth2-chall.c.diff?r1=1.42&r2=1.43&f=h upstream: https://github.com/openssh/openssh-portable/commit/5b64f85bb811246c59ebab70aed331f26ba37b18 upstream_openssh: needed precise_openssh: released (1:5.9p1-5ubuntu1.6) trusty_openssh: released (1:6.6p1-2ubuntu2.2) trusty/esm_openssh: released (1:6.6p1-2ubuntu2.2) vivid_openssh: released (1:6.7p1-5ubuntu1.2) devel_openssh: released (1:6.7p1-6ubuntu1) vivid/stable-phone-overlay_openssh: pending (1:6.7p1-5ubuntu1.2) vivid/ubuntu-core_openssh: released (1:6.7p1-5ubuntu1.2)