|
OPIE, as used in OpenSSH and possibly other programs, contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker systematically attempts authentication for a list of usernames, which will disclose the presence of valid accounts due to the way OPIE challenges for authentication.
|