Disclosure of potentially sensitive timing information in OpenSSH - #VU254
Published: August 2, 2016 / Updated: August 22, 2016
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive timing information.
The vulnerability exists in OpenSSH. A remote attacker can detect timing differences in the ssh(1) and sshd(8) MAC verification for Encrypt-then-MAC (EtM) mode transport MAC algorithms.
Successful exploitation of this vulnerability may result in disclosure of system information.
Affected software
openssh (Debian package)
openssh (Ubuntu package)