Red Hat Security Advisory 2017-2029-01

Discussion in 'News Aggregator' started by Packet Storm, 2 Aug 2017.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2017-2029-01 - OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server. The following packages have been upgraded to a later upstream version: openssh. Security Fix: A covert timing channel flaw was found in the way OpenSSH handled authentication of non-existent users. A remote unauthenticated attacker could possibly use this flaw to determine valid user names by measuring the timing of server responses.

    Continue reading...
     

Share This Page

Loading...