PT-2006-5964 · Openssh · Openssh

Publicado

2006-10-10

·

Atualizado

2018-10-17

·

CVE-2006-5229

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSH portable version 4.1
Description The issue allows remote attackers to determine valid usernames via timing discrepancies, where responses take longer for valid usernames than invalid ones. This is possibly dependent on the use of manually-set passwords that cause delays when processing /etc/shadow due to an increased number of rounds.
Recommendations For OpenSSH portable version 4.1, consider configuring the system to use a different password authentication method to minimize the risk of exploitation. As a temporary workaround, restrict access to the sshtime demonstration tool until a more secure configuration is implemented. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-5229

Produtos afetados

Openssh