OpenSSH could be made to expose timing information over the network.. ========================================================================== Ubuntu Security Notice USN-6887-1 July 09, 2024 openssh vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: OpenSSH could be made to expose timing information over the network. Software Description: - openssh: secure shell (SSH) for secure access to remote machines Details: Philippos Giavridis, Jacky Wei En Kung, Daniel Hugenroth, and Alastair Beresford discovered that the OpenSSH ObscureKeystrokeTiming feature did not work as expected. A remote attacker could possibly use this issue to determine timing information about keystrokes. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS openssh-client 1:9.6p1-3ubuntu13.4 openssh-server 1:9.6p1-3ubuntu13.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6887-1 CVE-2024-39894 Package Information: https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.4 . A critical OpenSSH flaw can allow remote attackers to exploit timing info, compromising data confidentiality. All users must update to mitigate this risk. OpenSSH Advisory, Ubuntu Timing Exposure, Remote Access Security, SSH Timing Information. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.