DescriptionOpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
|National Vulnerability Database|
SUSE Security Advisories:
- SUSE-SR:2005:005, published Friday, Feb 18th 2005 18:00 MEST
SUSE Timeline for this CVECVE page created: Fri Jun 28 00:19:03 2013
CVE page last modified: Fri Oct 7 12:45:27 2022