The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.
Observable Discrepancy
Observable Discrepancy
-
Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
---|---|---|---|---|---|
debian/openssh | deb | debian | 12 | >=1:9.2p1-2+deb12u2 | Not yet available |
debian/openssh | deb | debian | 13 | >=1:9.7p1-5 | Not yet available |
debian/openssh | deb | debian | unstable | >=1:9.7p1-5 | Not yet available |
debian/openssh | deb | debian | 11 | >=1:8.4p1-5+deb11u3 | Not yet available |
debian/openssh | deb | debian | 10 | >=1:7.9p1-10+deb10u2 | Not yet available |
Severity and metrics
No CVSS data available from this source.
2.2
-
2.2
-
2.2
-
2.2
-