Description
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 14 | | | 1:7.2p2-6 |
 alpine v3.2 | | =5.1_p1-r1 || =5.1_p1-r2 || =5.1p1-r0 || =5.2_p1-r0 || =5.2_p1-r1 || =5.2_p1-r2 || =5.2_p1-r3 || =5.3_p1-r3 || =5.4_p1-r0 || =5.4_p1-r1 || =5.4_p1-r2 || =5.4_p1-r3 || =5.5_p1-r0 || =5.6_p1-r0 || =5.6_p1-r1 || =5.8_p1-r0 || =5.8_p1-r1 || =5.8_p1-r2 || =5.8_p2-r0 || =5.8_p2-r1 || =5.8_p2-r2 || =5.9_p1-r0 || =5.9_p1-r1 || =5.9_p1-r2 || =6.0_p1-r0 || =6.1_p1-r0 || =6.1_p1-r1 || =6.1_p1-r2 || =6.2_p1-r0 || =6.2_p2-r0 || =6.2_p2-r1 || =6.2_p2-r2 || =6.3_p1-r0 || =6.3_p1-r1 || =6.3_p1-r2 || =6.4_p1-r0 || =6.4_p1-r1 || =6.6_p1-r0 || =6.6_p1-r1 || =6.6_p1-r2 || =6.6_p1-r3 || =6.6_p1-r4 || =6.6_p1-r5 || =6.6_p1-r6 || =6.7_p1-r0 || =6.8_p1-r0 || =6.8_p1-r1 || =6.8_p1-r2 || =6.8_p1-r3 || =6.8_p1-r4 || =6.8_p1-r5 || =6.8_p1-r6 || >=0 <6.8_p1-r7 | 6.8_p1-r7 |
 alpine v3.3 | | =5.1_p1-r1 || =5.1_p1-r2 || =5.1p1-r0 || =5.2_p1-r0 || =5.2_p1-r1 || =5.2_p1-r2 || =5.2_p1-r3 || =5.3_p1-r3 || =5.4_p1-r0 || =5.4_p1-r1 || =5.4_p1-r2 || =5.4_p1-r3 || =5.5_p1-r0 || =5.6_p1-r0 || =5.6_p1-r1 || =5.8_p1-r0 || =5.8_p1-r1 || =5.8_p1-r2 || =5.8_p2-r0 || =5.8_p2-r1 || =5.8_p2-r2 || =5.9_p1-r0 || =5.9_p1-r1 || =5.9_p1-r2 || =6.0_p1-r0 || =6.1_p1-r0 || =6.1_p1-r1 || =6.1_p1-r2 || =6.2_p1-r0 || =6.2_p2-r0 || =6.2_p2-r1 || =6.2_p2-r2 || =6.3_p1-r0 || =6.3_p1-r1 || =6.3_p1-r2 || =6.4_p1-r0 || =6.4_p1-r1 || =6.6_p1-r0 || =6.6_p1-r1 || =6.6_p1-r2 || =6.6_p1-r3 || =6.6_p1-r4 || =6.6_p1-r5 || =6.6_p1-r6 || =6.7_p1-r0 || =6.8_p1-r0 || =6.8_p1-r1 || =6.8_p1-r2 || =6.9_p1-r0 || =6.9_p1-r1 || =6.9_p1-r2 || =6.9_p1-r3 || =6.9_p1-r4 || =6.9_p1-r5 || =7.1_p1-r0 || =7.1_p1-r1 || =7.1_p2-r0 || =7.2_p1-r0 || =7.2_p2-r0 || >=0 <7.2_p2-r1 | 7.2_p2-r1 |
 alpine v3.4 | | =5.1_p1-r1 || =5.1_p1-r2 || =5.1p1-r0 || =5.2_p1-r0 || =5.2_p1-r1 || =5.2_p1-r2 || =5.2_p1-r3 || =5.3_p1-r3 || =5.4_p1-r0 || =5.4_p1-r1 || =5.4_p1-r2 || =5.4_p1-r3 || =5.5_p1-r0 || =5.6_p1-r0 || =5.6_p1-r1 || =5.8_p1-r0 || =5.8_p1-r1 || =5.8_p1-r2 || =5.8_p2-r0 || =5.8_p2-r1 || =5.8_p2-r2 || =5.9_p1-r0 || =5.9_p1-r1 || =5.9_p1-r2 || =6.0_p1-r0 || =6.1_p1-r0 || =6.1_p1-r1 || =6.1_p1-r2 || =6.2_p1-r0 || =6.2_p2-r0 || =6.2_p2-r1 || =6.2_p2-r2 || =6.3_p1-r0 || =6.3_p1-r1 || =6.3_p1-r2 || =6.4_p1-r0 || =6.4_p1-r1 || =6.6_p1-r0 || =6.6_p1-r1 || =6.6_p1-r2 || =6.6_p1-r3 || =6.6_p1-r4 || =6.6_p1-r5 || =6.6_p1-r6 || =6.7_p1-r0 || =6.8_p1-r0 || =6.8_p1-r1 || =6.8_p1-r2 || =6.9_p1-r0 || =6.9_p1-r1 || =6.9_p1-r2 || =6.9_p1-r3 || =6.9_p1-r4 || =6.9_p1-r5 || =7.1_p1-r0 || =7.1_p1-r1 || =7.1_p2-r0 || =7.2_p1-r0 || =7.2_p2-r0 || >=0 <7.2_p2-r1 | 7.2_p2-r1 |
 debian 13 | | | 1:7.2p2-6 |
 debian 11 | | | 1:7.2p2-6 |
 debian 12 | | | 1:7.2p2-6 |
 rpm rhel7 | | | 0:7.4p1-11.el7 |
 rpm rhel5 | | - | - |
 rpm rhel6 | | | 0:5.3p1-123.el6_9 |