CVE-2019-12953: inconsistent failure delay that may lead to revealing valid usernames

Related Vulnerabilities: CVE-2019-12953   CVE-2018-15599  

Debian Bug report logs - #1009062
CVE-2019-12953: inconsistent failure delay that may lead to revealing valid usernames

version graph

Reported by: Guilhem Moulin <guilhem@debian.org>

Date: Wed, 6 Apr 2022 18:27:01 UTC

Severity: important

Tags: security

Found in versions dropbear/2016.74-5+deb9u1, dropbear/2018.76-5, dropbear/2011.54-1

Fixed in version dropbear/2019.78-1

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org:
Bug#1009062; Package src:dropbear. (Wed, 06 Apr 2022 18:27:03 GMT) (full text, mbox, link).


Acknowledgement sent to Guilhem Moulin <guilhem@debian.org>:
New Bug report received and forwarded. (Wed, 06 Apr 2022 18:27:03 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Guilhem Moulin <guilhem@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2019-12953: inconsistent failure delay that may lead to revealing valid usernames
Date: Wed, 6 Apr 2022 20:22:26 +0200
[Message part 1 (text/plain, inline)]
Source: dropbear
Version: 2011.54-1
Severity: important
Tags: security
Control: found -1 2016.74-5+deb9u1
Control: found -1 2018.76-5
Control: fixed -1 2019.78-1

CVE-2019-12953: Dropbear 2011.54 through 2018.76 has an inconsistent
failure delay that may lead to revealing valid usernames.  This is a
different issue than CVE-2018-15599.

Upstream fix: https://hg.ucc.asn.au/dropbear/rev/228b086794b7 .

-- 
Guilhem.
[signature.asc (application/pgp-signature, inline)]

Marked as found in versions dropbear/2016.74-5+deb9u1. Request was from Guilhem Moulin <guilhem@debian.org> to submit@bugs.debian.org. (Wed, 06 Apr 2022 18:27:03 GMT) (full text, mbox, link).


Marked as found in versions dropbear/2018.76-5. Request was from Guilhem Moulin <guilhem@debian.org> to submit@bugs.debian.org. (Wed, 06 Apr 2022 18:27:04 GMT) (full text, mbox, link).


Marked as fixed in versions dropbear/2019.78-1. Request was from Guilhem Moulin <guilhem@debian.org> to submit@bugs.debian.org. (Wed, 06 Apr 2022 18:27:04 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Thu Apr 7 13:09:18 2022; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.