Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenSSH S/Key 远程信息泄露漏洞
Vulnerability Description
当ChallengeResponseAuthentication被启用时,OpenSSH允许远程攻击者借助S/KEY,试图进行鉴别,从而决定用户帐户的位置。如果用户帐户存在的话,这会显示不同的响应。
CVSS Information
N/A
Vulnerability Type
N/A