SA-2024-095 - OpenSSH Timing Attacks (CVE-2024-39894)
Summary OpenSSH sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystr...
