Back to search
CVE-2013-4434
Published: Oct 25, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
55173
third-party-advisory
x_refsource_SECUNIA
https://matt.ucc.asn.au/dropbear/CHANGES
x_refsource_CONFIRM
62993
vdb-entry
x_refsource_BID
[oss-security] 20131015 Re: CVE Request: dropbear sshd daemon 2013.59 release
mailing-list
x_refsource_MLIST
openSUSE-SU-2013:1696
vendor-advisory
x_refsource_SUSE
https://support.citrix.com/article/CTX216642
x_refsource_CONFIRM
openSUSE-SU-2013:1616
vendor-advisory
x_refsource_SUSE
https://secure.ucc.asn.au/hg/dropbear/rev/d7784616409a
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now