Candidate: CVE-2013-4434 PublicDate: 2013-10-25 23:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4434 Description: Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=726118 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_dropbear: upstream: https://secure.ucc.asn.au/hg/dropbear/rev/d7784616409a upstream_dropbear: released (2013.59) lucid_dropbear: ignored (reached end-of-life) precise_dropbear: ignored (reached end-of-life) precise/esm_dropbear: DNE (precise was needed) quantal_dropbear: ignored (reached end-of-life) raring_dropbear: ignored (reached end-of-life) saucy_dropbear: ignored (reached end-of-life) trusty_dropbear: not-affected (2013.60-1ubuntu2) trusty/esm_dropbear: DNE (trusty was not-affected [2013.60-1ubuntu2]) utopic_dropbear: not-affected (2013.60-1ubuntu2) vivid_dropbear: not-affected (2013.60-1ubuntu2) vivid/stable-phone-overlay_dropbear: DNE vivid/ubuntu-core_dropbear: DNE wily_dropbear: not-affected (2013.60-1ubuntu2) xenial_dropbear: not-affected (2013.60-1ubuntu2) yakkety_dropbear: not-affected (2013.60-1ubuntu2) zesty_dropbear: not-affected (2013.60-1ubuntu2) devel_dropbear: not-affected (2013.60-1ubuntu2)