peter bassill · operator
$ cve CVE-2006-5229 JSON

CVE-2006-5229 EXPLOIT

2.6
LOW · CVSS 2.0 · EPSS 58.3% (pctl 99)

Patch early

A public exploit exists.

Description

OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via timing discrepancies in which responses take longer for valid usernames than invalid ones, as demonstrated by sshtime. NOTE: as of 20061014, it appears that this issue is dependent on the use of manually-set passwords that causes delays when processing /etc/shadow due to an increased number of rounds.

Scoring

CVSS2.6 (LOW, v2.0)
VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
EPSS58.33% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2006-10-10
Last modified2026-06-16

Affected (2)

VendorProduct
novellsuse linux
openbsdopenssh

Public exploits

SourceTitleDate
exploit-dbPortable OpenSSH 3.6.1p-PAM/4.1-SuSE - Timing Attack2007-02-13

References

→ the Explorer  ·  watch your stack  ·  NVD