Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g5qj-pfmg-p3jp

Опубликовано: 02 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

EPSS

Процентиль: 71%
0.00688
Низкий

7.5 High

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 3.1
redhat
больше 1 года назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 7.5
nvd
больше 1 года назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 7.5
msrc
около 1 года назад

Описание отсутствует

CVSS3: 7.5
debian
больше 1 года назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks aga ...

EPSS

Процентиль: 71%
0.00688
Низкий

7.5 High

CVSS3

Дефекты

CWE-367