Summary
OpenSSH sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.
Products Potentially Affected
OS/Product |
Exposure |
IQ Engine (HiveOS) |
No |
Repair Recommendations
None.
Please see the full security advisory article here for more details and updates.