OpenSSH 4.4 was released and mentions: * On portable OpenSSH, fix a GSSAPI authentication abort that could be used to determine the validity of usernames on some platforms. This could only affect RHEL4 as previous RHEL did not support GSSAPI (We currently don't know if this would affect Linux)
openssh-3.9p1 is not vulnerable to this abort - but see #234643.
This flaw does affect RHEL5 is seems. I'm reopening this bug against RHEL5.
*** This bug has been marked as a duplicate of 234643 ***