CVE-2024-39894
EUVD-2024-3835002.07.2024, 18:15
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openbsd | openssh | 9.5 ≤ 𝑥 ≤ 9.7 | ADP |
Debian Releases
Ubuntu Releases
References