Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2003-0190
Description:OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.
Test IDs: 1.3.6.1.4.1.25623.1.0.52938   1.3.6.1.4.1.25623.1.0.11574   1.3.6.1.4.1.25623.1.1.12.2004.34.1   1.3.6.1.4.1.25623.1.0.50971   1.3.6.1.4.1.25623.1.0.50470   1.3.6.1.4.1.25623.1.0.65514  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2003-0190
BugTraq ID: 7467
http://www.securityfocus.com/bid/7467
Bugtraq: 20030430 OpenSSH/PAM timing attack allows remote users identification (Google Search)
http://marc.info/?l=bugtraq&m=105172058404810&w=2
Bugtraq: 20030806 [OpenPKG-SA-2003.035] OpenPKG Security Advisory (openssh) (Google Search)
http://marc.info/?l=bugtraq&m=106018677302607&w=2
http://lists.grok.org.uk/pipermail/full-disclosure/2003-April/004815.html
http://lab.mediaservice.net/advisory/2003-01-openssh.txt
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A445
RedHat Security Advisories: RHSA-2003:222
http://www.redhat.com/support/errata/RHSA-2003-222.html
RedHat Security Advisories: RHSA-2003:224
http://www.redhat.com/support/errata/RHSA-2003-224.html
TurboLinux Advisory: TLSA-2003-31
http://www.turbolinux.com/security/TLSA-2003-31.txt




© 1998-2025 E-Soft Inc. All rights reserved.