Information disclosure in OpenSSH - CVE-2024-39894

 

Information disclosure in OpenSSH - CVE-2024-39894

Published: July 1, 2024 / Updated: January 8, 2025


Vulnerability identifier: #VU93514
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-39894
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due a logic error in ObscureKeystrokeTiming implementation within the ssh client. A local user with ability to passively observe SSH sessions can recover sensitive input, such as password for the su or sudo programs.


Affected software

OpenSSH
Oracle Solaris
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
IBM i
FreeBSD
Desktop Applications Module
Basesystem Module
openSUSE Leap
Anolis OS
Junos OS
Junos OS Evolved
Ubuntu
macOS
LANTIME Operating System Firmware (LTOS)
openssh-server (Ubuntu package)
openssh-client (Ubuntu package)
openssh-doc
openssh-sk-dummy
openssh-server
openssh-keycat
openssh-clients
openssh-askpass
openssh
openssh-fips
openssh-debuginfo
openssh-helpers
openssh-clients-debuginfo
openssh-debugsource
openssh-server-config-disallow-rootlogin
openssh-cavs-debuginfo
openssh-server-debuginfo
openssh-askpass-gnome-debuginfo
openssh-helpers-debuginfo
openssh-cavs
openssh-common-debuginfo
openssh-common
openssh-askpass-gnome-debugsource
openssh-askpass-gnome

How to mitigate CVE-2024-39894

Install updates from vendor's website.

OpenSSH - update to 9.8p1
Oracle Solaris - update to 11.4 SRU 71
LANTIME Operating System Firmware (LTOS) - update to 7.08.014
Junos OS - addressed in versions 24.2R1-S2, 24.2R2, 24.4R1
Junos OS Evolved - addressed in versions 24.2R1-S2-EVO, 24.2R2-EVO, 24.4R1-EVO
openssh-server (Ubuntu package) - update to 1:9.6p1-3ubuntu13.4
openssh-client (Ubuntu package) - update to 1:9.6p1-3ubuntu13.4
openssh-doc - update to 9.6p1-3
openssh-sk-dummy - update to 9.6p1-3
openssh-server - update to 9.6p1-3
openssh-keycat - update to 9.6p1-3
openssh-clients - update to 9.6p1-3
openssh-askpass - update to 9.6p1-3
openssh - update to 9.6p1-3
openssh-clients - update to 9.6p1-150600.6.6.1
openssh-fips - update to 9.6p1-150600.6.6.1
openssh-debuginfo - update to 9.6p1-150600.6.6.1
openssh - update to 9.6p1-150600.6.6.1
openssh-helpers - update to 9.6p1-150600.6.6.1
openssh-clients-debuginfo - update to 9.6p1-150600.6.6.1
openssh-debugsource - update to 9.6p1-150600.6.6.1
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.6.1
openssh-cavs-debuginfo - update to 9.6p1-150600.6.6.1
openssh-server-debuginfo - update to 9.6p1-150600.6.6.1
openssh-askpass-gnome-debuginfo - update to 9.6p1-150600.6.6.1
openssh-helpers-debuginfo - update to 9.6p1-150600.6.6.1
openssh-server - update to 9.6p1-150600.6.6.1
openssh-cavs - update to 9.6p1-150600.6.6.1
openssh-common-debuginfo - update to 9.6p1-150600.6.6.1
openssh-common - update to 9.6p1-150600.6.6.1
openssh-askpass-gnome-debugsource - update to 9.6p1-150600.6.6.1
openssh-askpass-gnome - update to 9.6p1-150600.6.6.1
macOS - update to 15.0 24A335

External References

Related Security Bulletins