Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g5qj-pfmg-p3jp

Опубликовано: 02 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

EPSS

Процентиль: 81%
0.01584
Низкий

7.5 High

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 3.1
redhat
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 7.5
nvd
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 7.5
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks aga ...

EPSS

Процентиль: 81%
0.01584
Низкий

7.5 High

CVSS3

Дефекты

CWE-367