Wind River Support Network

HomeDefectsLIN1021-1506
Fixed

LIN1021-1506 : Security Advisory - openssh - CVE-2016-20012

Created: Sep 15, 2021    Updated: Jul 19, 2022
Resolved Date: Jul 19, 2022
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session.

CREATE(Triage):(User=admin) CVE-2016-20012 (https://nvd.nist.gov/vuln/detail/CVE-2016-20012)
Live chat
Online