OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.
References
Configurations
No configuration.
History
21 Nov 2024, 09:28
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2024/07/03/6 - | |
References | () http://www.openwall.com/lists/oss-security/2024/07/23/4 - | |
References | () http://www.openwall.com/lists/oss-security/2024/07/23/6 - | |
References | () http://www.openwall.com/lists/oss-security/2024/07/28/3 - | |
References | () https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-July/000158.html - | |
References | () https://security.netapp.com/advisory/ntap-20240712-0004/ - | |
References | () https://www.openssh.com/txt/release-9.8 - | |
References | () https://www.openwall.com/lists/oss-security/2024/07/02/1 - |
11 Sep 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
28 Jul 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
23 Jul 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
23 Jul 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
12 Jul 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 Jul 2024, 14:18
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-367 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
03 Jul 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
03 Jul 2024, 12:53
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
02 Jul 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-02 18:15
Updated : 2024-11-21 09:28
NVD link : CVE-2024-39894
Mitre link : CVE-2024-39894
CVE.ORG link : CVE-2024-39894
JSON object : View
Products Affected
No product.
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition