CVE-2024-39894
Name
CVE-2024-39894
Description
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.
NVD Severity
medium
Other trackers
CVE
,
NVD
,
CERT
,
CVE Details
,
CIRCL
,
Arch Linux
,
Debian
,
Red Hat
,
Ubuntu
,
Gentoo
,
SUSE (Bugzilla)
,
SUSE (CVE)
,
Mageia
Mailing lists
oss-security
,
full-disclosure
,
bugtraq
Exploits
Exploit DB
,
Metasploit
Forges
GitHub (
code
,
issues
), Aports (
code
,
issues
)
References
Type
URI
https://www.openssh.com/txt/release-9.8
https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-July/000158.html
https://www.openwall.com/lists/oss-security/2024/07/02/1
mailing-list
http://www.openwall.com/lists/oss-security/2024/07/03/6
https://security.netapp.com/advisory/ntap-20240712-0004/
mailing-list
http://www.openwall.com/lists/oss-security/2024/07/23/4
mailing-list
http://www.openwall.com/lists/oss-security/2024/07/23/6
mailing-list
http://www.openwall.com/lists/oss-security/2024/07/28/3
Match rules
CPE URI
Source package
Min version
Max version
n/a
== n/a
== n/a
Vulnerable and fixed packages
Source package
Branch
Version
Maintainer
Status
openssh
3.19-main
9.6_p1-r1
Natanael Copa <ncopa@alpinelinux.org>
possibly vulnerable