Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-39894

Опубликовано: 02 июл. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

РелизСтатусПримечание
devel

released

1:9.6p1-3ubuntu17
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
fips-updates/bionic

not-affected

code not present
fips-updates/focal

not-affected

code not present
fips-updates/xenial

not-affected

code not present
fips/bionic

not-affected

code not present
fips/focal

not-affected

code not present

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
mantic

not-affected

code not present
noble

not-affected

code not present
upstream

ignored

frozen on openssh 7.5p

Показывать по

EPSS

Процентиль: 81%
0.01584
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 3.1
redhat
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 7.5
nvd
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVSS3: 7.5
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
12 месяцев назад

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks aga ...

CVSS3: 3.1
redos
12 месяцев назад

Уязвимость openssh

EPSS

Процентиль: 81%
0.01584
Низкий

7.5 High

CVSS3

Уязвимость CVE-2024-39894