Logo
componentopenssh
Name
openssh
Version
10.3p1
Type
library
Description
-
Licenses
BSD-3-ClauseBSD-2-ClausePublic Domain
PURL
-
CPE
cpe:2.3:a:openbsd:openssh:10.3:p1:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
2025.02.x
9.9p2

Vulnerabilities#


Name
Analysis
Description
Exploitable
OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. NOTE: this is disputed by the Supplier, who states "we do not consider it to be the application's responsibility to defend against platform architectural weaknesses."
Exploitable
OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.