Описание
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.
Ссылки
- Broken Link
- Broken Link
- Third Party Advisory
- Third Party Advisory
- Broken Link
- Broken Link
- Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- Broken Link
- Third Party Advisory
- Broken Link
- Broken Link
- Broken Link
- Third Party Advisory
- Third Party Advisory
- Broken Link
- Broken Link
- Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- Broken Link
- Third Party Advisory
- Broken Link
Уязвимые конфигурации
Одно из
Одно из
Одновременно
Одновременно
EPSS
5 Medium
CVSS2
Дефекты
Связанные уязвимости
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enable ...
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.
Уязвимости операционной системы Red Hat Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
EPSS
5 Medium
CVSS2