OpenSSH Authentication Execution Path Timing Information Leakage Weakness
BID:7343
Info
OpenSSH Authentication Execution Path Timing Information Leakage Weakness
| Bugtraq ID: | 7343 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2002 12:00AM |
| Updated: | Apr 15 2002 12:00AM |
| Credit: | Discovery of this issue is credited to Sebastian Krahmer. |
| Vulnerable: |
OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 p1 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 3.0 p1 OpenSSH OpenSSH 3.0 OpenSSH OpenSSH 2.9.9 OpenSSH OpenSSH 2.9 p2 OpenSSH OpenSSH 2.9 p1 OpenSSH OpenSSH 2.9 OpenSSH OpenSSH 2.5.2 OpenSSH OpenSSH 2.5.1 OpenSSH OpenSSH 2.5 OpenSSH OpenSSH 2.3 OpenSSH OpenSSH 2.2 |
| Not Vulnerable: | |
Discussion
OpenSSH Authentication Execution Path Timing Information Leakage Weakness
A timing attack has been described in OpenSSH that could allow a remote user to determine if a username is valid. This information can be ascertained through analysis of the response time during authentication.
It is currently not known whether this issue has been addressed in recent versions of OpenSSH. It is possible that other SSH implementations may also be affected, though this has not been confirmed.
A timing attack has been described in OpenSSH that could allow a remote user to determine if a username is valid. This information can be ascertained through analysis of the response time during authentication.
It is currently not known whether this issue has been addressed in recent versions of OpenSSH. It is possible that other SSH implementations may also be affected, though this has not been confirmed.
Exploit / POC
OpenSSH Authentication Execution Path Timing Information Leakage Weakness
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
OpenSSH Authentication Execution Path Timing Information Leakage Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
OpenSSH Authentication Execution Path Timing Information Leakage Weakness
References:
References:
- Execution path timing analysis of UNIX daemons (Sebastian Krahmer)