OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.

Project Subscriptions

Vendors Products
Openbsd Subscribe
Openssh Subscribe
Openpkg Subscribe
Openpkg Subscribe
Enterprise Linux Subscribe
Siemens Subscribe
Scalance X204rna Subscribe
Scalance X204rna Ecc Subscribe
Scalance X204rna Ecc Firmware Subscribe
Scalance X204rna Firmware Subscribe
Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-34-1 OpenSSH information leakage
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-08T01:43:36.108Z

Reserved: 2003-04-01T00:00:00

Link: CVE-2003-0190

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2003-05-12T04:00:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2003-0190

cve-icon Redhat

Severity : Low

Publid Date: 2003-04-30T00:00:00Z

Links: CVE-2003-0190 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses