Lucene search

K
redhatRedHatRHSA-2017:2563
HistoryAug 31, 2017 - 1:09 p.m.

(RHSA-2017:2563) Moderate: openssh security update

2017-08-3113:09:34
access.redhat.com
95

0.107 Low

EPSS

Percentile

95.1%

OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.

Security Fix(es):

  • A covert timing channel flaw was found in the way OpenSSH handled authentication of non-existent users. A remote unauthenticated attacker could possibly use this flaw to determine valid user names by measuring the timing of server responses. (CVE-2016-6210)