OpenSSH S/Key Remote Information Disclosure Vulnerability

OpenSSH contains an information-disclosure vulnerability when S/Key authentication is enabled. This issue occurs because the application fails to properly obscure the existence of valid usernames in authentication attempts.

Exploiting this vulnerability allows remote users to test for the existence of valid usernames. Knowledge of system users may aid in further attacks.


 

Privacy Statement
Copyright 2010, SecurityFocus