OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.
References
Configurations
No configuration.
History
28 Jul 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2024-07-02 18:15
Updated : 2024-07-28 21:15
NVD link : CVE-2024-39894
Mitre link : CVE-2024-39894
CVE.ORG link : CVE-2024-39894
JSON object : View
Products Affected
No product.
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition