PT-2003-2507 · Openssh+1 · Openssh+1

Ashar Voultoiz

·

Publicado

2003-12-31

·

Atualizado

2024-07-08

·

CVE-2003-1562

CVSS v2.0

7.6

Alta

VetorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSH versions 3.6.1p2 and earlier
Description The issue allows remote attackers to potentially determine if the password step of a multi-step authentication is successful by using timing differences. This occurs when PermitRootLogin is disabled and PAM keyboard-interactive authentication is used.
Recommendations For OpenSSH versions 3.6.1p2 and earlier, consider updating to a version that includes a fix for this issue, as the current version allows for potential timing attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
CVE-2003-1562

Produtos afetados

Alt Linux
Openssh