Описание
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 1:9.6p1-3ubuntu17 |
esm-infra-legacy/trusty | not-affected | code not present |
esm-infra/bionic | not-affected | code not present |
esm-infra/focal | not-affected | code not present |
esm-infra/xenial | not-affected | code not present |
fips-updates/bionic | not-affected | code not present |
fips-updates/focal | not-affected | code not present |
fips-updates/xenial | not-affected | code not present |
fips/bionic | not-affected | code not present |
fips/focal | not-affected | code not present |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | code not present |
esm-apps/bionic | not-affected | code not present |
esm-apps/focal | not-affected | code not present |
esm-apps/jammy | not-affected | code not present |
esm-apps/noble | not-affected | code not present |
focal | not-affected | code not present |
jammy | not-affected | code not present |
mantic | not-affected | code not present |
noble | not-affected | code not present |
upstream | ignored | frozen on openssh 7.5p |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks aga ...
EPSS
7.5 High
CVSS3