{"id":"openSUSE-SU-2021:1390-1","summary":"Security update for ssh-audit","details":"This update for ssh-audit fixes the following issues:\n\nssh-audit was updated to version 2.5.0\n\n* Fixed crash when running host key tests.\n* Handles server connection failures more gracefully.\n* Now prints JSON with indents when -jj is used (useful for\n  debugging).\n* Added MD5 fingerprints to verbose output.\n* Added -d/--debug option for getting debugging output.\n* Updated JSON output to include MD5 fingerprints. Note that\n  this results in a breaking change in the 'fingerprints'\n  dictionary format.\n* Updated OpenSSH 8.1 (and earlier) policies to include\n  rsa-sha2-512 and rsa-sha2-256.\n* Added OpenSSH v8.6 & v8.7 policies.\n* Added 3 new key exchanges:\n\n  + gss-gex-sha1-eipGX3TCiQSrx573bT1o1Q==\n  + gss-group1-sha1-eipGX3TCiQSrx573bT1o1Q==\n  + gss-group14-sha1-eipGX3TCiQSrx573bT1o1Q==\n* Added 3 new MACs:\n\n  + hmac-ripemd160-96\n  + AEAD_AES_128_GCM\n  + AEAD_AES_256_GCM\n\nUpdate to version 2.4.0\n\n* Added multi-threaded scanning support.\n* Added version check for OpenSSH user enumeration (CVE-2018-15473).\n* Added deprecation note to host key types based on SHA-1.\n* Added extra warnings for SSHv1.\n* Added built-in hardened OpenSSH v8.5 policy.\n* Upgraded warnings to failures for host key types based on SHA-1\n* Fixed crash when receiving unexpected response during host key\n  test.\n* Fixed hang against older Cisco devices during host key test &\n  gex test.\n* Fixed improper termination while scanning multiple targets when\n  one target returns an error.\n* Dropped support for Python 3.5 (which reached EOL in Sept.2020)\n* Added 1 new key exchange: sntrup761x25519-sha512@openssh.com.\n\n","modified":"2026-02-04T04:37:06.928768Z","published":"2021-10-20T18:07:44Z","related":["CVE-2018-15473"],"upstream":["CVE-2018-15473"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/F33WEA5KQR7XFYMXJPGRCG4IZX75GFRO/"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-15473"}],"affected":[{"package":{"name":"ssh-audit","ecosystem":"SUSE:Package Hub 15 SP3","purl":"pkg:rpm/suse/ssh-audit&distro=SUSE%20Package%20Hub%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.0-bp153.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"ssh-audit":"2.5.0-bp153.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:1390-1.json"}},{"package":{"name":"ssh-audit","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/ssh-audit&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.0-bp153.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"ssh-audit":"2.5.0-bp153.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:1390-1.json"}}],"schema_version":"1.7.3"}