Do your applications use this vulnerable package?
Test your applications
Overview
OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.
References
CVSS Score
4.3
low severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityNone
-
AvailabilityNone
- CVE
- CVE-2007-2768
- CWE
- CWE-200
- Snyk ID
- SNYK-DEBIAN10-OPENSSH-368925
- Disclosed
- 21 May, 2007
- Published
- 21 May, 2007