#VU93514 Information disclosure in OpenSSH - CVE-2024-39894
Published: July 1, 2024 / Updated: January 8, 2025
OpenSSH
OpenSSH
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due a logic error in ObscureKeystrokeTiming implementation within the ssh client. A local user with ability to passively observe SSH sessions can recover sensitive input, such as password for the su or sudo programs.