Disclosure of potentially sensitive timing information in OpenSSH - #VU254

 

Disclosure of potentially sensitive timing information in OpenSSH - #VU254

Published: August 2, 2016 / Updated: August 22, 2016


Vulnerability identifier: #VU254
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive timing information.

The vulnerability exists in OpenSSH. A remote attacker can detect timing differences in the ssh(1) and sshd(8) MAC verification for Encrypt-then-MAC (EtM) mode transport MAC algorithms.

Successful exploitation of this vulnerability may result in disclosure of system information.


Affected software

OpenSSH
openssh (Debian package)
openssh (Ubuntu package)

Remediation

Install the latest version of OpenSSH 7.3.


External References

Related Security Bulletins