Vulnerability Bulletins |
DSA-3626 openssh - security update |
|
| Affected software | Debian |
|
Eddie Harari reported that the OpenSSH SSH daemon allows userenumeration through timing differences when trying to authenticateusers. When sshd tries to authenticate a non-existing user, it will pickup a fixed fake password structure with a hash based on the Blowfishalgorithm. If real users passwords are hashed using SHA256/SHA512, thena remote attacker can take advantage of this flaw by sending largepasswords, receiving shorter response times from the server fornon-existing users. More info: https://www.debian.org/security/2016/dsa-3626 |
|






