Security expert: ‘Comically Bad’ libSSH vulnerability lets you log in to Linux servers without a password. Luckily, the flaw doesn’t appear to affect the majority of Linux distributions, BSD, Mac or Windows. The bug can be exploited if the client presents the server with a “SSH2_MSG_USERAUTH_SUCCESS” message in place of the. SSH2_MGS_REQUEST message which the server would expect to initiate authentication. The client pretends to be the server, and the server accepts that response.”]
Source: https://www.govinfosecurity.com/heads-up-patch-comically-bad-libssh-flaw-now-a-11626