Sensitive timing information disclosure in OpenSSH - #VU253
Published: August 2, 2016 / Updated: August 22, 2016
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive timing information.
The vulnerability exists in OpenSSH. A remote attacker may be able to observe timing differences in the ssh(1) and sshd(8) CBC padding oracle countermeasures.
Successful exploitation of this vulnerability may result in disclosure of system information.
Affected software
openssh (Debian package)
openssh (Ubuntu package)