Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-39894

Опубликовано: 02 июл. 2024
Источник: debian
EPSS Низкий

Описание

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensshfixed1:9.8p1-1package
opensshnot-affectedbookwormpackage
opensshnot-affectedbullseyepackage

Примечания

  • https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-July/000158.html

  • https://www.openwall.com/lists/oss-security/2024/07/02/1

EPSS

Процентиль: 81%
0.01584
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 3.1
redhat
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 7.5
nvd
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 7.5
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 3.1
redos
12 месяцев назад

Уязвимость openssh

EPSS

Процентиль: 81%
0.01584
Низкий