Bug 234645

Summary: Kerberos information leak
Product: Red Hat Enterprise Linux 3 Reporter: Miloslav Trmač <mitr>
Component: opensshAssignee: Jan F. Chadima <jchadima>
Status: CLOSED NEXTRELEASE QA Contact: Brian Brock <bbrock>
Severity: medium Docs Contact:
Priority: medium    
Version: 3.0Keywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-06-24 09:34:56 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Miloslav Trmač 2007-03-30 19:10:52 UTC
+++ This bug was initially created as a clone of Bug #234643 +++

From the openssh-4.3 changelog:
* Fix timing variance for valid vs. invalid accounts when attempting
  Kerberos authentication (Bugzilla #975)