Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12669
HistoryJan 15, 2019 - 9:20 a.m.

Information Disclosure

2019-01-1509:20:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
24

EPSS

0.107

Percentile

95.2%

openssh is vulnerable to information disclosure attacks. The vulnerability exists as sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.