Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-39894

Опубликовано: 02 июл. 2024
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

A flaw was found in OpenSSH. A logic error in the SSH ObscureKeystrokeTiming feature (on by default) rendered this feature ineffective. A passive observer could still detect which network packets contained real keystrokes when the countermeasure was active because fake and real keystroke packets were being sent unconditionally.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10opensshFix deferred
Red Hat Enterprise Linux 6opensshNot affected
Red Hat Enterprise Linux 7opensshNot affected
Red Hat Enterprise Linux 8opensshNot affected
Red Hat Enterprise Linux 9opensshNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-203
https://bugzilla.redhat.com/show_bug.cgi?id=2295273openssh: Logic error in ObscureKeystrokeTiming

EPSS

Процентиль: 81%
0.01584
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 7.5
nvd
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 7.5
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks aga ...

CVSS3: 3.1
redos
12 месяцев назад

Уязвимость openssh

EPSS

Процентиль: 81%
0.01584
Низкий

3.1 Low

CVSS3